Cryptographic processing device, cryptographic processing method, and cryptographic processing program
The cryptographic processing device addresses the challenge of error accumulation in fully homomorphic encryption by enabling multiplication of ciphertexts and fully realizing integer-wise arithmetic operations, thereby improving processing efficiency.
Patent Information
- Application Number
- JP2024025934
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2023-05-22
- Filing Date
- 2024-02-22
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2044-02-22
AI Technical Summary
Existing fully homomorphic encryption methods, such as those based on the Learning with Errors (LWE) problem, face challenges in efficiently performing integer-wise arithmetic operations due to error accumulation during calculations, which complicates the realization of all four arithmetic operations.
A cryptographic processing device is developed to enable multiplication of ciphertexts and fully realize integer-wise arithmetic operations by using a specific method involving the multiplication of first and second ciphertexts, followed by calculations using polynomials to determine the position of the plaintext in the operation result.
This approach allows for the complete realization of the four arithmetic operations in integer-wise TFHE, enhancing processing efficiency by enabling operations beyond simple addition and subtraction.
Smart Images

Figure 0007681926000060 
Figure 0007681926000061 
Figure 0007681926000062
Abstract
Description
[Technical field]
[0001] The present invention relates to a cryptographic processing device, a cryptographic processing method, and a cryptographic processing program. [Background technology]
[0002] Homomorphic encryption is an encryption method that allows data processing to be performed on encrypted data without decrypting the data. Additive homomorphic encryption is an encryption in which there is an operation between ciphertexts that corresponds to the addition between plaintexts, and multiplicative homomorphic encryption is an encryption in which there is an operation between ciphertexts that corresponds to the multiplication between plaintexts. Additive homomorphic encryption, which treats finite cyclic groups as integers and performs only additive operations (addition and subtraction), and multiplicative homomorphic encryption, which performs only multiplicative operations (multiplication), have long been known. Finite cyclic groups allow integer multiplication by repeated addition, so integer multiplication using plaintext is possible, and exponentiation calculations using plaintext are also possible by repeated multiplication. There is also ring homomorphic encryption, which processes both additive and multiplicative operations while keeping the data encrypted, and fully homomorphic encryption (FHE), which allows all operations including additive and multiplicative operations. One type of fully homomorphic encryption is based on the Learning with Errors (LWE) problem, which involves adding small errors to the plaintext during encryption that do not affect decryption.
[0003] In fully homomorphic encryption based on the LWE problem, errors accumulate as calculations are performed, so bootstrapping is performed to reduce the error components while still encrypting the data before the errors become too large to make decryption possible. The computation time of bootstrapping accounts for most of the computation time required for fully homomorphic encryption. In addition, because bootstrapping handles a huge amount of data, the amount of computation required is enormous. Therefore, in fully homomorphic encryption, it has been difficult to obtain the computation results within a practical time frame. A technique that dramatically improves this problem is TFHE (Fast Fully Homomorphic Encryption over the Torus), which is shown in Non-Patent Document 1 (referred to as the above paper in the following description). There are two types of homomorphic encryption: bit-wise homomorphic encryption, which has a binary plaintext and uses logical operations as the base, and integer-wise homomorphic encryption, which uses an entire integer as a single ciphertext as the plaintext. The TFHE described in Non-Patent Document 1 is a bit-wise type. Note that the plaintext of TFHE is a real number between 0 and 1 that is associated with a circular group. Therefore, by associating integers with intervals that divide the range of the circular group from 0 to 1 in order, it is possible to apply it as an integer-wise homomorphic encryption that has integers as plaintexts (see Non-Patent Document 2). [Prior art documents] [Patent documents]
[0004] [Non-Patent Document 1] TFHE:Fast Fully Homomorphic Encryption over the Torus. Journal of Cryptology, 33:34-91, 2020, I. Chillotti, N. Gama, M. Georgieva, and M. Izabachene [Non-Patent Document 2] Integerwise Functional Bootstrapping on TFHE, 2020, Hiroki Okada, Shinsaku Kiyomoto, and Carlos Cid Summary of the Invention [Problem to be solved by the invention]
[0005] If TFHE can be used as a homomorphic encryption method capable of integer-wise arithmetic operations, processing can be performed more efficiently than calculating each bit one by one. The above paper shows that the TLWE ciphertext used in TFHE is additively homomorphic to plaintexts in circular groups, and it is trivial that addition (subtraction) operations can be performed. On the other hand, as for multiplication, although the multiplication of integers and circular groups (ciphertexts) is defined because circular groups are Z-modules, it cannot be said to be trivial because multiplication between circular groups is not defined. One aspect of the present invention is to enable multiplication of ciphertexts and more completely realize the four arithmetic operations of integer-wise TFHE. [Means for solving the problem]
[0006] According to one aspect, the present invention provides a cryptographic processing device that processes a ciphertext, the ciphertext being a fully homomorphic ciphertext having a plaintext in which an integer is associated with a value to which an error having a predetermined variance is added within a predetermined value range, and which allows a predetermined operation between integers to be performed without decryption; The cryptographic processing device includes: As a process for the fully homomorphic ciphertext, a first ciphertext and a second ciphertext, each of which is additively homomorphic with respect to a plaintext, are multiplied by each other; In the multiplication, the cryptographic processing device A third ciphertext indicating the position of the plaintext in the operation result is calculated using a first polynomial having all the same coefficients on the operation result obtained by performing a homomorphic operation on a ciphertext based on the first ciphertext and a ciphertext based on the second ciphertext, and an operation is performed on the first ciphertext and the second ciphertext by performing a homomorphic operation on the operation result using a predetermined polynomial on the ciphertext obtained by reducing the range of the plaintext to within a predetermined range within the range. Effect of the Invention
[0007] According to one aspect of the present invention, the four arithmetic operations of an integer-wise TFHE can be more completely realized. [Brief description of the drawings]
[0008] [Figure 1] FIG. 2 is a diagram illustrating a functional configuration of a cryptographic processing device according to a first embodiment of the present invention. [Diagram 2] 2 is a diagram for explaining in detail a calculation process based on the functional configuration of FIG. 1. [Diagram 3] FIG. 1 is an image diagram for explaining a circular group that the TLWE cipher has as plaintext. [Figure 4] This is an image diagram of binary gate bootstrapping operation. [Diagram 5] FIG. 1 is a diagram illustrating an integer-wise application of TFHE. [Figure 6] FIG. 2 is a diagram illustrating an integer-wise TFHE according to the present embodiment. [Figure 7] FIG. 2 is a diagram illustrating an integer-wise TFHE according to the present embodiment. [Figure 8] FIG. 2 is a diagram illustrating an integer-wise TFHE according to the present embodiment. [Figure 9] FIG. 11 is a diagram illustrating a functional configuration of a cryptographic processing device according to a second embodiment of the present invention. [Figure 10] FIG. 10 is a diagram for explaining a calculation process based on the functional configuration of FIG. [Figure 11] 11 is a flowchart illustrating a multiplication process according to a first example of the present embodiment. [Figure 12] 11 is a flowchart illustrating a multiplication process according to a second example of the present embodiment. [Figure 13] FIG. 13 is a diagram illustrating a functional configuration of a cryptographic processing device according to a fourth embodiment of the present invention. [Figure 14] FIG. 14 is a diagram for explaining a calculation process based on the functional configuration of FIG. 13. [Figure 15] FIG. 13 is a diagram illustrating a functional configuration of a cryptographic processing device according to a fifth embodiment of the present invention. [Figure 16] FIG. 16 is a diagram for explaining a calculation process based on the functional configuration of FIG. [Figure 17] 10 is a diagram showing ciphertexts input and output to Gate Bootstrapping of the present embodiment. FIG. [Figure 18] FIG. 1 is a block diagram illustrating an embodiment of a computing device. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0009] Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings. In the following description, alphanumeric characters enclosed in [] indicate that it is a vector, and alphanumeric characters enclosed in {} indicate that it is a set. In addition, in this specification, the term "logical operation" refers to a binary or multi-valued operation.
[0010] [First Example] FIG. 1 is a diagram illustrating the functional configuration of a cryptographic processing device according to a first embodiment of the present invention. The cryptographic processing device 1 includes a control unit 10, a storage unit 20, a communication unit 25, and an input unit . The control unit 10 includes a reception unit 11, a first calculation unit 12, a second calculation unit 13, a third calculation unit 14, a fourth calculation unit 15, a fifth calculation unit 16, a first bootstrap unit (calculation unit) 17, a second bootstrap unit (calculation unit) 18, a third bootstrap unit (calculation unit) 19, and an output unit 35. The control unit 10 also includes a sixth calculation unit 41 and a seventh calculation unit 42 that divide the coefficient of the ciphertext by 2. The cryptographic processing device 1 performs multiplication of Integer-wise positive TLWE ciphertexts by using one half (right half) of the circular group that constitutes the ciphertext.
[0011] The reception unit 11 receives an input of a ciphertext to be subjected to an operation via the communication unit 25 or the input unit 26. Alternatively, the reception unit 11 receives an input of a ciphertext from another process executed by the cryptographic processing device 1. The sixth arithmetic unit 41 performs an operation of dividing the coefficient of the input ciphertext or the ciphertext output from the first arithmetic unit 12 by two. The seventh arithmetic unit 42 performs an operation of dividing the coefficient of the input ciphertext or the ciphertext output from the second arithmetic unit 13 by two. The first arithmetic unit 12 performs a first homomorphic operation on the input ciphertext or the ciphertext output from the sixth arithmetic unit 41 . The second arithmetic unit 13 performs a second homomorphic operation on the input ciphertext or the ciphertext output from the seventh arithmetic unit . The first bootstrap unit 17 performs first bootstrap on the ciphertext output from the first arithmetic unit 12 . The third arithmetic unit 14 performs a third homomorphic operation on the ciphertext output from the first arithmetic unit 12 and the ciphertext output from the first bootstrap unit 17 . The fourth arithmetic unit 15 performs a fourth homomorphic operation on the ciphertext output from the second arithmetic unit 13 and the ciphertext output from the first bootstrapping unit 17 . The first bootstrap unit 17 may perform first bootstrap on the ciphertext output from the second arithmetic unit 13 . In this case as well, the third arithmetic unit 14 performs a third homomorphic operation on the ciphertext output from the first arithmetic unit 12 and the ciphertext output from the first bootstrap unit 17. In addition, the fourth arithmetic unit 15 performs a fourth homomorphic operation on the ciphertext output from the second arithmetic unit 13 and the ciphertext output from the first bootstrap unit 17.
[0012] The second bootstrap unit 18 performs second bootstrap on the ciphertext output from the third calculation unit 14. The third bootstrap unit 19 performs third bootstrap on the ciphertext output from the fourth arithmetic unit 15 . The fifth arithmetic unit 16 performs a fifth homomorphic operation on the ciphertext output from the second bootstrap unit 18 and the ciphertext output from the third bootstrap unit 19 .
[0013] The first calculation unit 12, the second calculation unit 13, the third calculation unit 14, the fourth calculation unit 15, the fifth calculation unit 16, the sixth calculation unit 41, and the seventh calculation unit 42 are calculation processing units that realize the homomorphic calculation described below using software. The first bootstrap unit 17, the second bootstrap unit 18, and the third bootstrap unit 19 are arithmetic processing units that realize the gate bootstrapping process described below by software. At least one of the first calculation unit 12, the second calculation unit 13, the third calculation unit 14, the fourth calculation unit 15, the fifth calculation unit 16, the sixth calculation unit 41, the seventh calculation unit 42, the first bootstrap unit 17, the second bootstrap unit 18, the third bootstrap unit 19, and the output unit 35 may be realized in hardware.
[0014] The output unit 35 outputs the final calculation result to the outside of the cryptographic processing device 1 or to another processing process executed by the cryptographic processing device 1. The storage unit 20 can store input ciphertext, temporary files and temporary data used in operations on the ciphertext, and output ciphertext. The storage unit 20 can also store an encrypted database 60 . The storage unit 20 also stores a look-up table (LUT) that stores calculated values of coefficients of a test vector polynomial, which will be described below. The communication unit 25 connects the cryptographic processing device 1 to a network, enabling communication with external devices. By storing the encrypted database 60 in the storage unit 20 and providing the communication unit 25, the cryptographic processing device 1 can function as a database server. In this case, the cryptographic processing device 1 can accept an encrypted query from a terminal device as an external device, perform a search on the encrypted encrypted database 60, and respond with encrypted search results to the terminal device. The input unit 26 inputs, to the cryptographic processing device 1, ciphertext to be processed and a query for the encrypted database 60.
[0015] FIG. 2 is a diagram for explaining in detail the calculation process based on the functional configuration of FIG. The configuration shown in Figure 2 uses the Gate Bootstrapping proposed in the above paper. The Gate Bootstrapping of TFHE proposed in the above paper is described in detail below. As described above, the cryptographic processing device 1 performs multiplication of integer-wise TLWE ciphertexts (TLWE ciphertext ca, TLWE ciphertext cb). Here, the TLWE ciphertext ca is a ciphertext of plaintext integer a, and the TLWE ciphertext cb is a ciphertext of plaintext integer b. Both the TLWE ciphertext ca and the TLWE ciphertext cb are ciphertexts that use the right half plane of a circular group as the plaintext range, for example, with a positive integer as the plaintext. The cryptographic processing device 1 multiplies ciphertexts by each other using a technique called Quarter Square, which will be described below.
[0016] FIG. 2(A) shows the process of calculating ciphertexts corresponding to the sum (a+b) and difference (ab) of plaintext a and plaintext b. In FIG. 2A, the cryptographic processing device 1 inputs a TLWE ciphertext ca to a sixth arithmetic unit 41, and obtains a new TLWE ciphertext ca' by dividing the coefficient of the TLWE ciphertext ca by two. Furthermore, the cryptographic processing device 1 inputs the TLWE ciphertext cb to a seventh arithmetic unit 42, and obtains a new TLWE ciphertext cb' by dividing the coefficient of the TLWE ciphertext cb by two. The cryptographic processing device 1 inputs the TLWE ciphertext ca' and the TLWE ciphertext cb' to the first arithmetic unit 12, and performs homomorphic addition (ca'+cb') (first homomorphic operation) on the TLWE ciphertext ca' and the TLWE ciphertext cb' to obtain a new TLWE ciphertext cc1.
[0017] In addition, the cryptographic processing device 1 inputs the TLWE ciphertext ca' and TLWE ciphertext cb' to the second operation unit 13, and performs homomorphic subtraction of the TLWE ciphertext cb' from the TLWE ciphertext ca' (ca'-cb') (second homomorphic operation) to obtain a new TLWE ciphertext cc2. The cryptographic processing device 1 inputs the TLWE ciphertext cc1 or the TLWE ciphertext cc2 to the first bootstrap unit 17, and performs gate bootstrap on the TLWE ciphertext cc1 or the TLWE ciphertext cc2 using a flat test vector polynomial T1(X) whose all coefficients are 1 / 4, to obtain a new TLWE ciphertext cd. The cryptographic processing device 1 inputs the TLWE ciphertext cc1 and the TLWE ciphertext cd to the third arithmetic unit 14, and performs homomorphic addition (cc1+cd) (third homomorphic operation) between the TLWE ciphertext cc1 and the TLWE ciphertext cd to obtain a new TLWE ciphertext cc1'. The cryptographic processing device 1 inputs the TLWE ciphertext cc2 and the TLWE ciphertext cd to the fourth arithmetic unit 15, and performs homomorphic addition (cc2+cd) (fourth homomorphic operation) between the TLWE ciphertext cc2 and the TLWE ciphertext cd to obtain a new TLWE ciphertext cc2'.
[0018] FIG. 2(B) shows the process of calculating ciphertexts corresponding to the square of the sum (a+b) of plaintext a and plaintext b divided by 4, and the square of the difference (ab) divided by 4, respectively. In FIG. 2B, the cryptographic processing device 1 inputs the TLWE ciphertext cc1′ to the second bootstrap unit 18 and generates a test vector polynomial T p A functional bootstrapping (second bootstrapping) is performed using (X) to obtain a new ciphertext cf1. The cryptographic processing device 1 also inputs the TLWE ciphertext cc2′ to the third bootstrapping unit 19 and generates a test vector polynomial T m Perform Functional Bootstrapping (third Bootstrapping) using (X) to obtain new ciphertext cf2.
[0019] FIG. 2(C) shows the process of calculating the multiplication result obtained by subtracting the square of the difference (ab) divided by 4 from the square of the sum (a+b) of plain text a and plain text b divided by 4. In FIG. 2C, the cryptographic processing device 1 inputs the TLWE ciphertext cf1 and the TLWE ciphertext cf2 to the fifth operation unit 16, and performs homomorphic subtraction (fifth homomorphic operation) of the TLWE ciphertext cf2 from the TLWE ciphertext cf1 to obtain a new TLWE ciphertext cg.
[0020] This section provides details on Gate Bootstrapping as explained in TFHE. Gate Bootstrapping is a technique for making fully homomorphic encryption practical, which was previously considered impractical due to the huge amount of data and computation time required. The TFHE in the above paper uses a cryptosystem called TLWE cryptosystem, which is an LWE (Learning with Errors) cryptosystem constructed on a circular group, to realize various homomorphic logical operations (and ultimately any operation such as addition and multiplication) between TLWE ciphertexts at high speed and with small data size while reducing errors during calculation.
[0021] The input for Gate Bootstrapping in TFHE is a TLWE ciphertext encrypted with a private key. In TFHE, fully homomorphic encryption (FHE) is realized based on TLWE ciphertext. TLWE cryptography is a special case of LWE cryptography, which is a type of lattice cryptography (LWE cryptography defined on a circular group). It is known that TLWE encryption is additively homomorphic, and additive operations between TLWE-encrypted plaintexts can be performed without decrypting the ciphertext.
[0022] FIG. 3 is an image diagram for explaining a circular group that the TLWE cipher has as a plaintext. The TLWE cipher advances from 0 with real number precision and returns to 0 when it reaches 1. Any point on the circle group {T} shown in Figure 3 is used as the plaintext, and the vicinity of 0 (including error) and the vicinity of μ (including error) are used as plaintext. Points on the circle group {T} are also referred to herein as "elements." A cryptographic processing device that handles TFHE performs common homomorphic operations such as additive operations between such TLWE ciphertexts, and by using Gate Bootstrapping to keep the error in the operation results within an appropriate range, it realizes fully homomorphic encryption (FHE) that allows logical operations to be performed again (at a later stage).
[0023] [TLWE cipher] Explain the TLWE cipher. As elements on the circle group {T}, prepare a vector [a] consisting of N uniformly distributed random numbers. Also prepare a secret key vector [s] consisting of N numbers randomly chosen from the binary values 0 and 1. If the mean is the plaintext μ and e is a random number with a Gaussian (normal) distribution and a predetermined variance α, then the set ([a],[s]·[a]+e) is an example of a TLWE ciphertext. The average value of e when an infinite number of TLWE ciphertexts are generated for the same plaintext μ is the plaintext μ, where μ is a plaintext without errors and e is a plaintext with errors. Note that "·" represents the inner product of vectors. The same applies hereafter. If we define the above [s]·[a]+e as b, the TLWE ciphertext can be expressed as ([a], b). φ s (([a],b))=b-[s]·[a]=e is the function that decrypts TLWE ciphertext. Since TLWE ciphertext encrypts plaintext by adding the inner product of the secret key vector and random number vector and an error, it is possible to decrypt the TLWE ciphertext with an error by calculating the inner product of the secret key vector and the random number vector. At this time, if the secret key vector is unknown, the components that make up the inner product cannot be calculated, and therefore decryption is not possible.
[0024] This TLWE encryption is additively homomorphic, meaning that addition operations between TLWE ciphertexts can be performed without decrypting the ciphertexts. Add the two TLWE ciphertexts ([a], b) and ([a'], b') as is to obtain ([a]+[a'], b+b'), and then use the above decryption function φ s If you enter φs (([a]+[a'],b+b'))=(b+b')-[s]·([a]+[a'])=(b-[s]·[a])+(b'-[s]·[a'])=φ s ([a],b)+φ s ([a'],b') This gives us the sum of the two plaintexts. This proves that the TLWE ciphertext is an "additively homomorphic encryption". In the TFHE described in the above paper, various calculations are achieved by repeatedly performing additive operations on the TLWE ciphertext with errors added to the plaintext, and reducing the errors by gate bootstrapping.
[0025] In what follows, a "trivial ciphertext" such as ([0],μ) is a TLWE ciphertext that can be decrypted with any private key, i.e., a ciphertext that can be decrypted with any private key to decrypt the same plaintext. In ([0],μ), [0] represents the zero vector. "Trivial ciphertext" can be treated as TLWE ciphertext, but it essentially contains the plaintext as is. The TLWE ciphertext ([0],μ) is decrypted by the decryption function φ s When multiplied by φ s Since (([0],μ))=μ-[s]·0=μ, and the secret key [s] is multiplied by the zero vector [0] and disappears, the plaintext μ can be easily obtained. Such a ciphertext is nothing but a trivial ciphertext for the plaintext μ.
[0026] We explain the finite cyclic groups used in Gate Bootstrapping of TFHE. Gate Bootstrapping utilizes the properties of the quotient ring of a polynomial ring as a finite cyclic group. Explain that there are finite cyclic groups in the quotient ring of a polynomial ring. A polynomial of degree n is generally n x n +a n-1 x n-1 +…+a 0 This is expressed as: All these sets form a commutative group for the sum of polynomials f(x) + g(x). Also, the product of polynomials, f(x)g(x), has properties similar to a commutative group, except that an inverse does not necessarily exist. Such a group is called a monoid. The distributive law holds for sums and products of polynomials as follows: f(x){g(x)+g'(x)}=f(x)g(x)+f(x)g'(x) Therefore, if we define the sum and product of polynomials as elements, they form a "ring", which is called a polynomial ring.
[0027] In TFHE, we use a polynomial ring whose coefficients are the circle group {T}, and denote such a polynomial ring as T[X]. Let T(X), which is an element of the polynomial ring, be T[X](X n If we decompose it into the form X+T[X], and then take out and collect only the second term (the remainder), this also has the properties of a "ring," so we obtain the remainder ring of the polynomial ring. In TFHE, the quotient ring of a polynomial ring is defined as T[X] / (X n +1).
[0028] The polynomial ring T[X] / (X n +1), using any coefficient μ(μ∈T), Polynomial F(X)=μX n-1 +μX n-2 +···+μX+μ Take out. When we multiply an element F(X) in the quotient ring of a polynomial ring by X, we get μX n-1 +μX n-2 +···+μX-μ, and the coefficient of the highest degree term changes from positive to negative and appears as a constant term. This is because the terms with degrees n-2 or less remain constant even after multiplying by X. n +1 cannot be divided, but the highest degree term is μX n =μ(X n +1)-μ. n Since we are considering the remainder when dividing by +1, only the remainder -μ on the right-hand side remains. Multiplying it by X again gives us μX n-1 +μX n-2 +···+μX 2 The same thing happens again: -μX-μ (the coefficient of the highest order term flips from positive to negative and appears as a constant term). Repeat this process n times to get -μX n-1 -μX n-2 ...-μX-μ and the coefficients of all terms are negative.
[0029] If we continue multiplying by X, -μX n-1 -μX n-2 -μX+μ -μX n-1 -μX n-2 +μX+μ The coefficient of the highest degree term flips from negative to positive and appears as a constant term. If you repeat this 2n times, you get the element F(X)=μX n-1 +μX n-2 Returning to +···+μX+μ, in this way, the top-order coefficient (μ) appears in the bottom-order constant term with its sign inverted (-μ), resulting in an overall shift of one term. That is, polynomial F(X)=μX n-1 +μX n-2 +···+μX+μ is the quotient ring T[X] / (X n +1), it is a generator of a finite cyclic group of order 2n. In TFHE, the cryptographic processing device realizes fully homomorphic encryption by utilizing the properties of a polynomial F(X) based on a remainder ring of such a polynomial ring. Regardless of whether the exponent of X is positive or negative, multiplying an element F(X) of the quotient ring of a polynomial ring n times by X reverses the signs of all the terms, and multiplying it 2n times restores the signs of all the terms. Also, X -1 Since multiplying by is the inverse operation of multiplying X, -1 If you continue to multiply it, the opposite change will occur compared to multiplying it by X, -1Multiplying it n times inverts all the terms, and multiplying it 2n times returns it to its original state. From the above, we can see that the element F(X) of the quotient ring of the polynomial ring has the same structure as X or X -1 Multiplying it n times will invert the signs of all the terms, and multiplying it 2n times will restore the signs of all the terms. In this cyclic group, because it can be rotated in either direction, it is sometimes expressed as -n times or -2n times for convenience. Note that this is merely a convenient expression for explaining the theory, and when implementing the present invention, for example, X a When multiplying by -b times, X -a Even if you apply it b times, X 2n-a may be applied b times, and other transformations may be performed if the same result can be achieved.
[0030] [TRLWE cipher] In addition to the TLWE cipher, Gate Bootstrapping uses a cipher called the TRLWE cipher. This section explains the TRLWE encryption. The R in TRLWE stands for ring, and TRLWE is an LWE encryption scheme built on rings. Like TLWE, TRLWE is also an additively homomorphic encryption scheme. The ring in TRLWE cryptography is the remainder ring T[X] / (X n +1). To obtain the TRLWE encryption, we use the polynomial ring T[X] / (X n +1) at random. In practice, the n coefficients of the n-1 degree polynomial are selected from the circle group {T} as uniformly distributed random numbers. If the degree of the polynomial is n-1, then X n Let polynomial a(X) be a polynomial of degree n-1, since it cannot be divided by +1 and there is no need to consider the remainder.
[0031] Randomly select n values from the two values 0 and 1 and construct the polynomial s(X) that will be the secret key below. s(X)=s n-1 Xn-1 +s n-2 X n-2 +···s 1 X+s 0 n random numbers e i The average value is the plaintext μ i Let the random numbers be Gaussian (normal) distributed with variance α, and then construct the following polynomial e(X) from these. e(X)=e n-1 X n-1 +e n-2 X n-2 +··e 1 X+e 0 s(X) a(X) + e(X) is expressed as f(X)(X n +1)+b(X) to obtain b(X). As a result, the TRLWE ciphertext obtained is (a(X), b(X)). Like the TLWE encryption, the TRLWE encryption uses random numbers for encryption, so an infinite number of ciphertexts can be generated for the same secret key and plaintext. In addition, the TRLWE encryption code has the same structure as the TLWE encryption code. s ((a(X),b(X))=b(X)-s(X)·a(X)+g(X)(X n +1), φ s T[X] / (X n The decryption function is defined as g(X) being the element of b(X) + 1. In other words, (b(X)-s(X) a(X))mod(X n +1) serves as the decoding function. mod means the remainder of the division.
[0032] [Gadget Decomposition] Explain Gadget Decomposition. The coefficients of the polynomial used in the TRLWE ciphertext are real numbers between 0 and 1, which are elements of the circle group {T} in FIG. 3, and have only a decimal part. The operation of decomposing this into several bits in binary notation is defined as Gadget Decomposition (Dec) in TFHE of the above paper. For example, if the degree n of the polynomial F(X) of the TRLWE ciphertext is n=2, then one unit of division is Bg=2. 2 Then, decompose it into l=3 elements, where each element is between -Bg / 2 and Bg / 2. The TRLWE ciphertext is a combination of two polynomials, such as (a(X), b(X)) above. Therefore, the TRLWE ciphertext d can be regarded as a two-dimensional vector whose elements are polynomials that are the elements of the remainder ring of the polynomial ring. For example, d=[0.75X 2 +0.125X+0.5,0.25X 2 +0.5X+0.375] Therefore, in the following, each element is written as Bg -1 =Decompose into the form of a sum of powers of 0.25.
[0033] On the circle group {T}, 0.75=-0.25, so d=[0.75X 2 +0.125X+0.5,0.25X 2 +0.5X+0.375] =[-0.25X 2 +0.125X+0.5,0.25X 2 +0.5X+0.25+0.125] = [0.25 × (-X 2 +2)+0.25 2 ×2X+0.25 3 ×0,0.25×(X 2 +2X+1)+0.25 2 ×2+0.25 3 ×0] It can be broken down as follows. Therefore, when Gadget Decomposition is performed, Dec(d) = [-X 2 +2,2X,0,X 2 +2X+1,2,0] This becomes the vector.
[0034] We also define an operator H that converts a vector back to a ciphertext. Based on the above example, The matrix TIFF0007681926000001.tif3034 is the inverse transform operator H. The TRLWE ciphertext d is obtained by calculating Dec(d) H. The lower bits are rounded off.
[0035] For a TRLWE ciphertext d, the operation of obtaining [v] such that ||d-[v]·H|| is the minimum value can also be said to be a gadget decomposition, where || is the norm (length) of the vector. Generate 2l TRLWE ciphertexts Zi=(a(X),b(X)), calculated using a polynomial generated from random numbers whose coefficients of e(X) have a mean of 0 and a variance of α. Then, the plaintext μ is encrypted as follows to obtain the following ciphertext k. TIFF0007681926000002.tif2643The ciphertext that can be expressed as this ciphertext k will be called the TRGSW ciphertext. The TRGSW ciphertext constitutes the Bootstrapping Key used below.
[0036] Explain Bootstrapping Key. The Bootstrapping Key is used as a method to encrypt a private key for use in Gate Bootstrapping. In addition to the secret key [s] (Nth degree) used for the TLWE ciphertext, each element of the secret key [s'] for encrypting the secret key [s] for use in Gate Bootstrapping is selected as a binary value of 0 or 1. The degree of the private key [s'] must be the same as the degree n of the polynomial used in the TRLWE encryption. Create a TRGSW ciphertext for each element of the private key [s]. When decrypted with the private key [s'], φ s’ Create 2l (el) TRLWE ciphertexts Zj such that (Zj)=0. And, according to the structure of the TRGSW ciphertext above, Let's say TIFF0007681926000003.tif2539. The set of TRGSW ciphertexts constructed using different Zj for each element of the secret key [s] is called the Bootstrapping Key (BK). In other words, BK is a set of N TRGSW ciphertexts.
[0037] The cross product of the TRGSW ciphertext BKi and the TRLWE ciphertext d is BKi×d=Dec(d)·BKi It is defined as: Gadget Decomposition is an operation to obtain [v] such that ||d-[v]·H|| is the minimum value for the TRLWE ciphertext d. Therefore, [v] = Dec(d) and the error (ε a (X),ε b Using (X), [v] H=d+(ε a (X),ε b (X)). As a result, BKi×d=Dec(d)·BKi The result is TIFF0007681926000004.tif2243. The left half calculates the dot product, and the right half calculates [v] H=d+(ε a (X),ε b Substituting (X), we get The result is TIFF0007681926000005.tif1490, which is the same as calculating the sum of the three ciphertexts c1, c2, and c3 below. TIFF0007681926000006.tif1945TRLWE encryption is an additively homomorphic encryption method, so adding two ciphertexts together is the same as adding two plaintexts together. C 1 is Z j Since it is the sum of several times of s’ (c 1 ) all have an expected value of 0. Also, the decoded φ s’ (c 3 ) is set to be sufficiently small, including the subsequent calculations, since the magnitude of the absolute value of each coefficient of the plaintext polynomial can be adjusted by the system parameters.
[0038] Then, φ s’ (BKi×d)=φ s’ (s i × d), but s i Whether s is 0 or 1, the calculation result is the sum of the three ciphertexts c1, c2, and c3. i It is not possible to determine whether it is 0 or 1. Two plaintext polynomials μ 0 , μ 1 The corresponding TRLWE ciphertext d 0 , d 1 Suppose, d=d 1 -d 0 And finally, d 0 Adding these, we get the CMux function shown below. CMux(BK i ,d 0 ,d 1 )=BKi×(d 1 -d 0 )+d 0 =Dec(d 1 -d 0 )·BK i +d 0 The CMux function is i If is 0, the plaintext polynomial is μ 0 The TRLWE ciphertext is output without being decrypted, and s i If is 1, the plaintext polynomial is μ 1 The TRLWE ciphertext is output without being decrypted. The CMux function is a function whose plaintext polynomial is μ 0 Or μ 1 However, even if you look at the result, you cannot tell which one was chosen without decrypting it.
[0039] Binary Gate Bootstrapping for TFHE is performed using the various techniques described above. Binary Gate Bootstrapping consists of three steps: (1) BlindRotate, (2) SampleExtract, and (3) Public Key Switching, as described below.
[0040] FIG. 4 is a conceptual diagram of the operation of binary gate bootstrapping. Binary Gate Bootstrapping reduces the error of the homomorphic operation result between TLWE ciphertexts with respect to the plaintext through the three steps described below. In the following explanation, unless otherwise specified, the plaintext refers to the result of an operation between plaintexts that is the result of an operation between TLWE ciphertexts. In the circular group {T} in Figure 3, TLWE ciphertexts with plaintexts in the ranges 0 to 0.25(1 / 4) and 0.75(3 / 4) to 1 are converted into TLWE ciphertexts with plaintext of 0, and TLWE ciphertexts with plaintexts in the range 0.25(1 / 4) to 0.75(3 / 4) are converted into ciphertexts with plaintext of 0.25(1 / 4). During this conversion, the error added to the plaintext is within the range of ±1 / 16.
[0041] (1) BlindRotate BlindRotate is performed as the first step in Gate Bootstrapping. BlindRotate is the process of creating a TRLWE ciphertext from a TLWE ciphertext. In BlindRotate, we convert the trivial TRLWE ciphertext (0,T(X)) with polynomial T(X) as plaintext into X -φs(c’) The TRLWE ciphertext multiplied by is obtained without decryption. 0 indicates the 0th degree polynomial 0. Here, φs(c') is the plaintext obtained by applying the LWE ciphertext c' below to the decryption function. In BlindRotate, the following polynomial F(X) is used as a test vector, which is a finite cyclic group as described above. F(X)=μX n-1 +μX n-2 +…μX+μ where μ=1 / 8 X n / 2 The following polynomial T(X) obtained by multiplying T(X)=F(X) X n / 2 Prepare the following.
[0042] Suppose there is a TLWE ciphertext c obtained by encrypting plaintext μ1 with a secret key [s]. Each element of this TLWE ciphertext c = ([a], b) is multiplied by 2n and rounded off to obtain the LWE ciphertext c' = ([a'], b'). When the LWE ciphertext c'=([a'],b') is decrypted, μ1'=φ s (c') ≒ 2n × φ s (c) = 2nμ1. Because of rounding errors, the numbers may not match perfectly, but the larger n is, the smaller the error becomes. Prepare a trivial TRLWE ciphertext (0,T(X)) with polynomial T(X) as plaintext, A 0 =X -b’ ×(0,T(X))=(0,X -b’ ×T(X)). 0 indicates the 0th degree polynomial 0. In this case, since b' is an integer, the power can be naturally defined. In practice, it is sufficient to rotate the coefficients of each term of the polynomial of the TRLWE ciphertext a predetermined number of times. Hereafter, the above-mentioned Bootstrapping Key, BK i Using, in order, A i =CMux(BK i ,A i-1 ,X a’i A i-1 Here too, since a'i is an integer, the power of X can be naturally defined. Similarly, instead of calculating the power of X, we calculate the TRLWE ciphertext A i-1 It is sufficient to rotate the coefficients of each term of the polynomial, which is an element of the polynomial, a predetermined number of times.
[0043] Then, s i When is 0, the plaintext remains unchanged, and s i When is 1, X a’i are multiplied in order. Therefore, If you repeat this with TIFF0007681926000007.tif2849, The result is TIFF0007681926000008.tif749. Where: Since TIFF0007681926000009.tif629 is equal to the decoding function φs(c') with its sign inverted, TIFF0007681926000010.tif741. Here, φ s’ (A n ) is the polynomial T(X) plus X -1 is a polynomial multiplied by μ1' times, and A n is the ciphertext. At this point, we should clarify that the error component of the error-added plaintext e of the initially set TLWE ciphertext c is expressed as the amount of rotation of the polynomial T(X), and is not expressed as the magnitude of the coefficient values of each term. TFHE essentially reduces the error by this mechanism. In addition, for the plaintext μ1 of the TLWE ciphertext c related to BlindRotate, we add X to the polynomial T(X). -1 Since a unique value (up to 2n values by inverting n coefficients and their signs) corresponding to the number of times μ1' (= 2nμ1) is multiplied is obtained as the coefficient of the constant term of the plaintext polynomial, this can be considered as a kind of look-up table.
[0044] (2)SampleExtract TRLWE ciphertext A obtained by BlindRotate in (1) n The plaintext polynomial φ obtained by decrypting s’ (A n ), counting from the lower terms, we get n / 2-φ s The coefficient of the (c')th term is -μ, and if it becomes negative, the coefficient of the term from the top down will be -μ. TRLWE Ciphertext A n The plaintext polynomial φ obtained by decrypting s’ (A n ), if we look only at the constant term of φ s (c') is greater than or equal to n / 2 and less than 3n / 2, i.e., φ sIf (c) is within the range of 1 / 2±1 / 4, the constant term is μ. Otherwise, if φs(c) is within the range of ±1 / 4, the constant term is -μ. SampleExtract is the TRLWE ciphertext A obtained by BlindRotate in (1). n From this, we can obtain the plaintext polynomial φ without decrypting it. s’ (A n ) to obtain the TLWE ciphertext cs. As mentioned above, the error added to the initial input TLWE ciphertext c and the error added by rounding only affect the position of the boundary where the plaintext μ and -μ of the constant term switch, and the effect on the magnitude of the coefficient of the constant term is negligibly small. In other words, it can be interpreted as eliminating input errors. Also, the range within which the boundary where the plaintext value of the constant term changes can be moved without any problems is the error limit for which bootstrap processing can be performed correctly, and this is the mechanism that creates the trade-off described below.
[0045] The process for obtaining the TLWE ciphertext cs will now be described. All TRLWE ciphertexts have degree n-1, Taking TIFF0007681926000011.tif1134 and a polynomial, it can be expressed as (A(X),B(X)). When this is decrypted with the private key [s'], the polynomial of the private key is Put it as TIFF0007681926000012.tif636, It can be expanded as TIFF0007681926000013.tif7116.
[0046] For this, the following calculation is carried out: I get TIFF0007681926000014.tif82136. Since it is a "modulus ring of a polynomial ring", (X n +1), we get the remainder The result is TIFF0007681926000015.tif18156.
[0047] moreover, If you put TIFF0007681926000016.tif1046, The file name becomes TIFF0007681926000017.tif38143. The coefficients of each term of the plaintext polynomial can be found from TIFF0007681926000018.tif776. Of these, what we need is the coefficient of the constant term, so if we extract the coefficient for j=0, we get The result is TIFF0007681926000019.tif638. If you put TIFF0007681926000020.tif620, It can be transformed into a TLWE cipher decryption function, such as TIFF0007681926000021.tif8114.
[0048] In other words, the TRLWE ciphertext A obtained by BlindRotate in (1) n =(A(X),B(X)), the coefficients are When extracted as TIFF0007681926000022.tif1055, the original TRLWE ciphertext A n A new TLWE cipher ([a”],b 1 ) is obtained. This new TLWE ciphertext is the output of SampleExtract, and there are two types of error-free plaintext: -μ or μ. The obtained TLWE ciphertext is added to the trivial ciphertext ([0],μ) whose plaintext is μ to obtain the TLWE ciphertext cs=([a”],b1)+([0],μ). Specifically, since μ=1 / 8 in the polynomial F(X) serving as the test vector, ciphertexts of −1 / 8 and 1 / 8 are obtained at this stage. Adding to this the trivial TLWE ciphertext ([0],1 / 8) with plaintext μ=1 / 8 gives us -1 / 8+1 / 8=0 1 / 8+1 / 8=1 / 4 From this, a new TLWE ciphertext cs is obtained, which has one of the two plaintext values 0 or 1 / 4.
[0049] (3) Public Key Switching The TLWE ciphertext cs obtained by SampleExtract in (2) is encrypted with the private key [s'], not the private key [s]. Therefore, it is necessary to replace the key of the TLWE ciphertext cs with the secret key [s] without decrypting the TLWE ciphertext cs, and return it to a state encrypted with the secret key [s]. Therefore, we will explain the Public Key Switching technique. The secret key [s] of the TLWE ciphertext used in TFHE is an N-dimensional vector. This is used to encrypt the secret key [s'] of the n-th vector used when creating the Bootstrapping Key. That is, TIFF0007681926000023.tif746 and private key s' i The value of is encrypted as an element of the circle group {T}, a value shifted to each digit when real numbers from 0 to 1 are expressed in binary. The private key is [s]. The "number of digits", t, is a system parameter. When the ciphertext KS created in this way is decrypted with the private key [s], The result is TIFF0007681926000024.tif737. This is the "key switching key". As mentioned above, the TLWE ciphertext cs = ([a], b) obtained in (2) is a value of 0 or 1 / 4 encrypted with the private key [s']. The number of elements of [a] is n, the same as the private key [s']. If we convert each of these into a t-bit fixed-point number, we get It can be written in the format TIFF0007681926000025.tif735. At this stage the error increases, but the maximum absolute value can be constrained by system parameters. As part of the Public Key Switching process, the following TLWE ciphertext cx is calculated. The term TIFF0007681926000026.tif862([0],b) is a trivial ciphertext, so when decrypted it gives b. When we calculate the result of decrypting the TLWE ciphertext cx, we get The file is TIFF0007681926000027.tif8118. s' i Since is a constant for j, we can factor it out as Enter TIFF0007681926000028.tif749 and substitute the formula that was decomposed into fixed decimal points above. TIFF0007681926000029.tif977As a result, The file will be TIFF0007681926000030.tif530, which means the key change was successful. The formula for calculating the TLWE ciphertext cx above is Extracting the Σ inside TIFF0007681926000031.tif862 The file is TIFF0007681926000032.tif629. This means TIFF0007681926000033.tif757, so s' i If s' is 0, the plaintext becomes 0, which is the TLWE ciphertext. i If is 1, then a i Only when the jth decimal place of s' is 1 in binary notation, 1 is added to the jth decimal place of the TLWE ciphertext. i If and only if is 1, then a i It can be said that the value is broken down into its binary digits and reconstructed as the contents of the TLWE ciphertext. And the outer By calculating TIFF0007681926000034.tif69 and adding the trivial ciphertext ([0],b), the content of the ciphertext is s' i a corresponds to the position where i This essentially means that the TLWE ciphertext is decrypted within the ciphertext.
[0050] The TLWE ciphertext cx obtained here is encrypted with the same secret key [s] as the TLWE ciphertext c that was input to Gate Bootstrapping. By performing the public key switching process, the TLWE ciphertext is restored to the TLWE ciphertext encrypted with the private key [s], and s If (c) is within ±1 / 4, then the plain text φ s (cx) is 0 plus an error, and φ s If (c) is in the range of 1 / 2±1 / 4, then the plaintext φ s (cx) is 1 / 4 plus some error. Through the above process, the result of Gate Bootstrapping was a TLWE ciphertext that was one of two values, 0 or 1 / 4, with an error within ±1 / 16. The maximum error does not depend on the input TLWE ciphertext c, but is fixed by the system parameters. Therefore, the system parameters are set so that the maximum error value is within ±1 / 16 of the input TLWE ciphertext. This makes it possible to perform the NAND operation any number of times. The NAND operation is a complete operation in the field of logical operations. In other words, if the NAND operation can be realized, all logical operations are possible by combining it. Therefore, by expressing any numerical value in binary, all operations including addition and multiplication become possible.
[0051] The errors in the "plaintext" of the TLWE ciphertext output from Gate Bootstrapping are the error added by rounding off the TLWE ciphertext, the error added by CMux, the error when it is converted to fixed decimal by Public Key Switching, etc. All of these errors can be constrained by system parameters, and the system parameters can be adjusted so that the error taking all of these into consideration is ±1 / 16. This completes the TFHE Gate Bootstrapping process.
[0052] As described above, TFHE is a bit-wise homomorphic encryption method that has 0 or non-0 as plaintext and performs logical operations. However, as explained in Figure 3, the plaintext is a real number between 0 and 1 that is associated with the circular group {T}. Therefore, by associating integers with the intervals that divide the circular group {T} in order, it can be used as an integer-wise homomorphic encryption method that has integers as plaintext. The above paper shows that the TLWE ciphertext used in TFHE is additively homomorphic to plaintexts in circular groups, and it is obvious that addition (subtraction) operations can be performed on it. Multiplication is further possible using the method described below. By enabling multiplication, TFHE can be used as a homomorphic encryption that can perform integer-wise arithmetic operations more completely, in addition to the already known addition and some multiplication. This allows processing to be performed more efficiently than if calculations were performed one bit at a time using bit-wise TFHE.
[0053] FIG. 5 is a diagram illustrating an integer-wise application of TFHE. As shown in Figure 5, the range of the circular group {T}, 0 to 1, is divided into t parts. In a TLWE ciphertext, the possible values of the plaintext are the t values obtained by dividing the range of 0 to 1, -(t / 2) to (t / 2)-1, and (t / 2)-1 is the maximum integer that can be recorded in one TLWE ciphertext. As shown in FIG. 5, when t=10 and the range of 0 to 1 is divided into 10 parts, the ciphertext can express integers of -5, -4, -3, -2, -1, 0, 1, 2, 3, and 4. These integer values are assigned to intervals centered on -5 / t, -4 / t, -3 / t, -2 / t, -1 / t, 0 / t, 1 / t, 2 / t, 3 / t, and 4 / t, which are obtained by dividing the range of 0 to 1 of the circular group {T} into t=10 parts. In this way, as shown in FIG. 5, it is possible to assign integers consecutively in a counterclockwise direction from the area that corresponds to the area centered on 1 / 2 in the values on the circular group and that is the minimum value when expressed as an integer.
[0054] As shown in Figure 5, 0 (1) on the circular group {T} is within the range of -1 / (2t) to 1 / (2t). The position of the plaintext of the ciphertext on the circular group {T} within the range (position on the circular group {T}) can be adjusted as necessary by adding or subtracting an offset based on, for example, 1 / (2t) to the state in Figure 5. Also, although there is no essential difference, it should be noted that in the embodiment described below, the meaning of the division number t of the circle group is different from that described in FIG.
[0055] 6 to 8 are diagrams for explaining the integer-wise TFHE in this embodiment. As shown in FIG. 6, the encrypted texts of the multiplier and multiplicand in this embodiment are obtained by dividing the entire range (0 to 1) of the circular group {T} into 2t parts. In addition, in FIG. 6 to FIG. 8, the range 0 to 1 of the circle group {T} may be set to −0.5 to 0.5. Increasing the value of t and dividing the circular group {T} into smaller parts makes it possible to increase the maximum integer value that can be recorded in the TLWE ciphertext, but dividing it too finely results in a problem in that the error range added to the plaintext becomes too small, reducing the strength of the ciphertext. This point will be explained later. An integer value is assigned to each 1 / (2t) interval into which the circular group {T} is divided, and the possible plaintext integer values of a TLWE ciphertext range from -t to t-1. t-1 is the maximum integer value that can be recorded in a single TLWE ciphertext, and -t is the minimum integer value that can be recorded in a single TLWE ciphertext. As in the case of Figure 5, Figure 6(b) shows the state where no offset is added to the plaintext (the offset to the plaintext is 0). Figure 6(a) shows the state where an offset of, for example, +1 / (4t) is added to the plaintext of the ciphertext shown in Figure 6(b). By adding an offset, it is possible to change the slicing of the circle group {T}. In the following description, the right and left halves of the circle group are assumed to conform to the state shown in FIG. 6(a) to which an offset of 1 / (4t) has been added.
[0056] In the state where no offset is added, shown in FIG. 6(b), 0(1) on the circle group {T} is within the slice from -1 / (4t) to 1 / (4t). By adding an offset as shown in Figure 6(a), the integer 0 can be associated with the slice (0 / 2t) starting from 0 on the circular group {T}. Other slices start from X / 2t (X is a plaintext integer). This allows 0 on the circular group to refer to the term of degree 0 of the test vector polynomial used when performing processing using bootstrapping, so adding an offset in this way has the advantage of making the order of coefficients more natural and easier to see. However, this is not a fundamental requirement, so a different offset can be adopted by making appropriate adjustments to the test vector, pre-processing, post-processing, etc. In Fig. 6(a), the plaintext with the offset is located in the center of each slice (e.g., the slice starting from 3 / (2t)) within the error range of ±1 / (4t). In this case, the mean of the normal distribution is, for example, 3 / (2t)+1 / (4t), and in most cases it is distributed within the error range of ±1 / (4t), so that the plaintext is distributed in the center of the slice starting from 3 / (2t). In FIG. 6(a), the plaintext with an offset is shown only in the slice of 3 / (2t), but this is merely an example, and all slices have plaintext with an offset added to the starting value.
[0057] The ciphertext in Figure 6 is created by dividing the right half of the circular group {T} into t pieces and the left half into t pieces. The right half of the circular group {T} corresponds to 0 and positive plaintext integers (0 to t-1), and the left half corresponds to negative plaintext integers (-1 to -t). The width of one block (slice) is 1 / (2t). Integer values are assigned to 2t slices of the range 0 to 1 (-1 / 2 to 1 / 2) of the circle group {T}, starting from -t / (2t) to (t-1) / (2t). Non-negative integers are assigned to slices starting at 0 / (2t), 1 / (2t), …, (t-3) / (2t), (t-2) / (2t), (t-1) / (2t) in the right-plane, while negative integers are assigned to slices starting at -t / (2t), -(t-1) / (2t), -(t-2) / (2t) …, -1 / (2t) in the left-plane. These slices are centered on the starting value with an offset of +1 / (4t). The 1 / (4t) offset is equivalent to half the slice width of 1 / (2t). If the 1 / (4t) offset is expressed as an integer, it can be conveniently expressed as an offset of +0.5.
[0058] As shown in Figure 6(a), when the range of the circular group is divided into 16 parts with 2t=16 (t=8), the right half of the circular group {T} can represent integers from 0 to 7 (=t-1), and the left half can represent integers from -8 (=-t) to -1. In other words, the entire ciphertext can represent integers from -8, -7, -6, -5, -4, -3, -2, -1, 0, 1, 2, 3, 4, 5, 6, and 7. These integer values are assigned to the intervals that divide the range of the circle group {T} into 2t = 16 intervals, starting with -8 / (2t), -7 / (2t), -6 / (2t), -5 / (2t), -4 / (2t), -3 / (2t), -2 / (2t), -1 / (2t), 0 / (2t), 1 / (2t), 2 / (2t), 3 / (2t), 4 / (2t), 5 / (2t), 6 / (2t), and 7 / (2t). Integers are assigned counterclockwise from the range starting with 1 / 2. Note that, taking the above offset of 0.5 into account, a slice on the right side starting at, say, 1 / (2t) is a slice centered at 1.5 / (2t), and a slice on the left side starting at, say, -8 / (2t) is a slice centered at -7.5 / (2t). The integers expressed with the offset included are, counterclockwise from the top, -7.5, -6.5, -5.5, -4.5, -3.5, -2.5, -1.5, -0.5, 0.5, 1.5, 2.5, 3.5, 4.5, 5.5, 6.5, and 7.5.
[0059] The cryptographic processing device 1 of this embodiment realizes multiplication of Integer-wise TLWE ciphertexts by the following method. The cryptographic processing device 1 uses a technique called Quarter Square. Quarter Square is a method of dividing (a+b) 2 and (ab) 2 Comparing the expansions of (a+b) 2 -(ab) 2 =a 2 +2ab+b 2 -(a 2 -2ab+b 2 )=4ab This is a technique that takes advantage of the fact that a is 4ab to obtain ab, which is the multiplication result of a and b. The calculations required for Quarter Square are: (1) Addition (a+b) and subtraction (ab) of a and b, (2) The square of the sum of a and b (a+b) 2 and the square of the subtraction result (ab) 2 , (3) Subtraction of the squares of the addition and subtraction results of a and b (a+b) 2 -(ab) 2 , (4) Divide the subtraction result 4ab by 4 to get ab. There are four types: Consider the case where the operations corresponding to (1) to (4) are performed on the ciphertexts a and b. The addition and subtraction of ciphertexts corresponding to the addition and subtraction of a and b in (1) and the subtraction of squares between ciphertexts corresponding to the subtraction of squares in (3) can be computed homomorphically between TLWE ciphertexts. In addition, the calculation of squaring the ciphertexts in (2) and the calculation of dividing the ciphertext by 4 in (4) (division of the plaintext by an integer) can be processed as one-variable functions using a lookup table (LUT). Therefore, multiplication using Quarter Square works well with the operations defined in TFHE.
[0060] The above (a+b) 2 -(ab) 2=4ab, the difference between the squares of the addition and subtraction results of a and b (a+b) 2 -(ab) 2 is always a multiple of 4. In this case, the square of (a+b) and the square of (ab) both have the same remainder when divided by 4. If you square (a+b), divide it by 4, and truncate the remainder, then subtract the quotient obtained by squaring (ab), dividing it by 4, and truncating the remainder from that quotient, you will get the same correct value as if you subtracted the square of (ab) from the quotient obtained by squaring (a+b) and dividing it by 4. Therefore, in FIG. 2, the cryptographic processing device 1 performs calculations on ciphertexts corresponding to (a+b) and (ab) in (A), and (a+b) in (B). 2 / 4, (ab) 2 In (C), the ciphertext corresponding to each of a and b is calculated. 2 / 4-(ab) 2 By performing an operation on the ciphertext corresponding to / 4, an operation on the ciphertext corresponding to the multiplication result of plaintext a and plaintext b is performed. In particular, when implementing the process of (B) using TFHE, it is preferable to store in advance in the LUT only the quotients obtained by squaring (a+b) and (ab) and dividing them by 4.
[0061] However, if you calculate the sum (a+b) or difference (ab) of a and b before squaring them, the range of the values after addition and subtraction will be doubled. If one were to naively perform calculations using the right half of the circular group (the domain of the plaintext) (for example, using only positive numbers), it would be necessary to perform operations that reference the LUT from the entire circular group, with the range doubled. The process of referencing a LUT using TFHE Bootstrapping is called Functional Bootstrapping, and in particular, the method of referencing a LUT from the entire surface of a circular group is called Full-Domain Functional Bootstrapping (FDFB). Various methods have been proposed for FDFB. Any of these methods can be used to realize Quarter Square, but in this embodiment, as an example of FDFB, a method called TOTA, disclosed in the paper "TOTA: Fully Homomorphic Encryption with Smaller Parameters and Stronger Security (https: / / eprint.iacr.org / 2021 / 1347)", is applied.
[0062] FIG. 7 is a diagram for explaining a method for performing FDFB using the TOTA method. In principle, division of points on a circle group is undefined. However, it is possible to force division by temporarily treating points on the circle group as real numbers. For example, as shown in Figure 7, if we consider the value 0.8 on the circle group {T} as the real number 0.8 and divide it by 2, we get 0.4. In general, division is considered to be the inverse operation of multiplication. Therefore, for example, a definition such as "finding r that satisfies 2r=0.8 on the circle group is called division" does not contradict other theories. In this case, r can take on two values, 0.4 and 0.9, because doubled values of these become 0.8 and 1.8, which are both equal to 0.8 on the circle group {T}. When dividing by 2, there is always one solution on the right half plane of the cycle group {T} and one on the left half plane, and forcing a division is always equivalent to choosing a value on the right half plane of the cycle group {T}.
[0063] Now, suppose there is a TLWE ciphertext cc consisting of a combination ([a], b) of vector [a] and scalar b using points on the circle group {T}. Let ([a'], b') be the TLWE ciphertext cc' obtained by forcibly dividing all elements of vector [a] of the TLWE ciphertext cc and the scalar b by 2 using the above method. As shown in Figure 7, if the value of the plaintext of the TLWE ciphertext cc on the cycle group is 0.8, the value of the plaintext of the TLWE ciphertext cc' obtained by forcibly dividing the TLWE ciphertext cc by 2 may be 0.4 or 0.9 on the cycle group, and it is not possible to know which it is without decrypting the TLWE ciphertext cc'. If the value of the original plaintext (the plaintext of the TLWE ciphertext cc) on the circle group is p (0.8 in the above case), then p=b-[s]·[a](mod 1) holds. (mod 1) is the remainder when dividing by 1, so we get only the decimal part of b-[s]·[a]. This can be interpreted as only the decimal parts matching on the left and right sides of the equal sign. In other words, there exists some integer n, and the calculation p=b-[s]·[a]+n holds in the world of real numbers.
[0064] Here, we substitute [a'] and b' of the TLWE ciphertext cc' into p=b-[s]·[a]+n. Since ([a],b) divided by 2 is ([a'],b'), [a] = 2[a'] and b = 2b'. As a result of the substitution, p = b - [s] · [a] + n = 2b' - 2[s] · [a'] + n. Since p / 2=(2b'-2[s]·[a']+n) / 2, p / 2 is b'-[s]·[a']+n / 2. Since this equation is valid in the world of real numbers, the decimal parts on both sides of the equal sign are naturally equal. Therefore, p / 2=b'-[s]·[a']+n / 2(mod 1) also naturally holds. Rearranging this gives p / 2-n / 2=b'-[s]·[a'], and the right-hand side is the plaintext of the TLWE ciphertext cc'. Therefore, the plaintext of the TLWE ciphertext cc' is p / 2-n / 2. Here, n is an unknown but existing integer, so the decimal part of n / 2 is either 0 or 0.5. Therefore, the plaintext of the TLWE ciphertext cc' is either p / 2 or p / 2+0.5. p / 2-0 is p / 2, and p / 2-0.5 is p / 2+0.5 because -0.5 and 0.5 are equal on the circle group.
[0065] Here, let u be the fractional part of n / 2, which is either 0 or 0.5. u is equivalent to the information on whether the integer n is even or odd. If the integer n is even, the fractional part u of n / 2 is 0, and if the integer n is odd, the fractional part u of n / 2 is 0.5. The reverse is also true. Denoted in terms of u, the plaintext of the TLWE ciphertext cc' is p / 2+u. Whether the plaintext of the TLWE ciphertext cc' is p / 2 or p / 2+0.5 can be obtained, while still encrypted, by checking whether the plaintext is on the right or left half plane of the circle group {T}. Specifically, the TLWE ciphertext cc' is bootstrapped using a flat test vector polynomial with all coefficients of 1 / 4 to obtain the TLWE ciphertext cd. This results in the TLWE ciphertext cd having 1 / 4 as plaintext if the plaintext is on the right half plane, and -1 / 4 as plaintext if the plaintext is on the left half plane. The TLWE ciphertext cd is a ciphertext that indicates whether the plaintext of the TLWE ciphertext cc' is on the right half plane or the left half plane. The TLWE ciphertext cd has a plaintext of u+1 / 4. The TLWE ciphertext cc'+cd obtained by homomorphically adding the TLWE ciphertext cd to the TLWE ciphertext cc' has p / 2+1 / 4 as the plaintext, since the unknown value u disappears from (p / 2+u)+(u+1 / 4)=p / 2+1 / 4.
[0066] Furthermore, homomorphic subtraction of the trivial ciphertext (0,1 / 4) from the TLWE ciphertext cc'+cd (cc'+cd-(0,1 / 4)) gives the TLWE ciphertext with p / 2 as plaintext. As a result, even if the original plaintext p (of the TLWE ciphertext cc) takes values in the full domain (0 to 1 over the entire circle group), the range of the plaintext in the TLWE ciphertext cc' can be reduced to the right half plane (0 to 0.5). However, each slice is half the size because the range of the entire plaintext has been halved.
[0067] If the TLWE ciphertext cc has plaintexts in the entire circle group, then the TLWE ciphertext cc' will use only the right half of the circle group as the plaintext range. Once this is achieved, since only the right half of the circle group is used, we can create a test vector polynomial from the LUT with the slice size similarly halved, and perform bootstrap as usual. BlindRotate, which accounts for the majority of the calculation time, is performed twice: once to obtain the TLWE ciphertext cd and once to actually refer to the LUT. When multiplying by Quarter Square, two FDFBs are required in total to look up the tables for square of the sum of x and y divided by 4 and square of the subtraction result divided by 4. The number of BlindRotates required for one FDFB is two, as shown above. Therefore, in a simple configuration, the number of BlindRotates required for the entire multiplication is four. In this embodiment, this speed is further increased.
[0068] [First Example] A method of multiplying ciphertext according to this embodiment will be described. The cryptographic processing device 1 sets the system parameters of TFHE. At this time, the cryptographic processing device 1 sets the range of error added to the plaintext in the ciphertext obtained after Gate Bootstrapping to ±1 / (8t 2 Set the system parameters so that the Suppose we have a TLWE ciphertext ca of a multiplicand (the number to be multiplied) and a TLWE ciphertext cb of a multiplier (the number to be multiplied). The TLWE ciphertexts ca and cb of the multiplier and multiplicand are TLWE ciphertexts with the structure shown in FIG. 6(a), in which the right half plane is divided into t pieces and the entire circular group {T} is divided into 2t pieces. In each of the TLWE ciphertext ca and TLWE ciphertext cb, the right half plane of the circular group {T} can correspond to plaintext that is a non-negative integer, and the left half plane can correspond to plaintext that is a negative integer. In this embodiment, however, only the right half plane is used as the plaintext range of the TLWE ciphertext ca and TLWE ciphertext cb. The TLWE ciphertext ca has as plaintext the real number a / (2t)+1 / (4t) corresponding to the integer a, which cannot be known without the private key. The TLWE ciphertext cb has as plaintext the real number b / (2t)+1 / (4t) corresponding to the integer b, which cannot be known without the secret key. The plaintexts of the TLWE ciphertexts ca and cb are a / (2t) and b / (2t), respectively, because the entire circular group is divided into 2t parts. As explained above, the +1 / (4t) offset added to the plaintext aligns the slice of the circular group starting from 0 with the integer 0, and positions the plaintext in the center of the slice. This offset is not mandatory. Since multiplication is commutative, the multiplier and multiplicand, i.e., the plaintext integers a and b, and the TLWE ciphertexts ca and cb, can be interchanged.
[0069] As explained with reference to FIG. 6(a), an offset a / (2t)+1 / (4t) is added to the plaintext in the TLWE ciphertext ca and the TLWE ciphertext cb. When the ciphertexts with an offset added to the plaintext are multiplied together, an offset equivalent to the product of the offsets is added to the plaintext resulting from the multiplication. This offset component disappears in subsequent operations, so it does not affect the calculation result (multiplication result). The offset value 1 / (4t) is an example and is not limited to this, but the polynomial and parameters must be adjusted depending on the offset value.
[0070] In Figure 6(a), on the left half of the circle group {T}, which handles negative numbers, the integers -t to -1 can be expressed using slices starting from -t / (2t) to -1 / (2t), going counterclockwise from the top. On the right half of the circle group {T}, which deals with 0 and positive numbers (non-negative numbers), integers 0 to t-1 can be represented using slices starting from 0 / (2t) to t-1 / (2t), going counterclockwise from the bottom. In this embodiment, the TLWE ciphertexts ca and cb to be multiplied have plaintexts only on the right half plane of the circular group {T} in FIG. 6(a).
[0071] Referring to Figure 2 and the explanation of FDFB above, we will explain in detail the multiplication process of ciphertexts using the Quarter Square method. In FIG. 2(A), the cryptographic processing device 1 obtains ciphertexts corresponding to (a+b) and (ab), respectively. The cryptographic processing device 1 (sixth arithmetic unit 41) divides the coefficient of the TLWE ciphertext ca by 2 to obtain a new TLWE ciphertext ca'. The cryptographic processing device 1 (seventh arithmetic unit 42) divides the coefficient of the TLWE ciphertext cb by 2 to obtain a new TLWE ciphertext cb'. As shown above, the plaintext of the TLWE ciphertext ca is a / (2t)+1 / (4t), and the plaintext of the TLWE ciphertext cb is b / (2t)+1 / (4t). Therefore, the TLWE ciphertext ca' has a / (4t)+1 / (8t)+u as plaintext, and the TLWE ciphertext cb' has b / (4t)+1 / (8t)+u' as plaintext. These u and u' are the values that appear when the ciphertext mentioned in the explanation of FDFB above is divided by 2. For the sake of distinction, the component of u that appears by dividing the modulus of the TLWE ciphertext cb by 2 is denoted as u'. The plaintexts of the TLWE ciphertext ca' and TLWE ciphertext cb' are half of the TLWE ciphertext ca and TLWE ciphertext cb before the modulus was divided by 2, and u(u'), the even / odd information of n that disappeared due to the operation (mod 1) on the circular group {T}, appears as 0 or 0.5.
[0072] The cryptographic processing device 1 (first arithmetic unit 12) performs a first homomorphic operation (ca'+cb'-(0,1 / (8t))) on the TLWE ciphertext ca' and the TLWE ciphertext cb' to obtain a new TLWE ciphertext cc1. The cryptographic processing device 1 (second arithmetic unit 13) performs a second homomorphic operation (ca'-cb'+(0,1 / (8t))) on the TLWE ciphertext ca' and the TLWE ciphertext cb' to obtain a new TLWE ciphertext cc2. The TLWE ciphertext cc1 obtained by the first homomorphic operation (homomorphic addition) is From a / (4t)+1 / (8t)+u+b / (4t)+1 / (8t)+u'-(0,1 / (8t)), We have (a+b) / (4t)+1 / (8t)+u+u' as plaintext. The TLWE ciphertext cc2 obtained by the second homomorphic operation (homomorphic subtraction) is From a / (4t)+1 / (8t)+u-(b / (4t)+1 / (8t)+u')+(0,1 / (8t)), We have (ab) / (4t)+1 / (8t)+u-u' as plaintext. The trivial TLWE ciphertext (0,1 / (8t)) added and subtracted in these homomorphic additions and subtractions is an inessential offset to align the boundary of the slice with the 0 of the circle group. This offset will be omitted in the following explanation.
[0073] Here, on the circle group {T}, 0.5 = -0.5. This can be interpreted as going half a circle from point 0 on the circle group {T} in either a clockwise or counterclockwise direction to the same point. And, from the above explanation, since both u and u' can only take the values of 0 or 0.5, on the circle group {T}, u = -u (if u is 0, then 0 = 0, and if u is 0.5, then 0.5 = -0.5), and u' = -u' (if u' is 0, then 0 = 0, and if u' is 0.5, then 0.5 = -0.5). Therefore, the components u+u' and u-u' contained in the plaintexts of the TLWE ciphertext cc1 and TLWE ciphertext cc2 always have the same value. Also, u+u' can only take on the value 0 or 0.5. If u is 0 and u' is 0, then u+u'=0 and u-u'=0. If u is 0 and u' is 0.5, u+u'=0.5, u-u'=-0.5⇒0.5 If u is 0.5 and u' is 0, then u+u'=0.5 and u-u'=0.5 If u is 0.5 and u' is 0.5, then u+u'=1⇒0, u-u'=0 Thus, u+u' is considered as a component u'' of unknown value, either 0 or +0.5.
[0074] The TLWE ciphertext cc1, which corresponds to the sum of the TLWE ciphertext ca and the TLWE ciphertext cb, and the TLWE ciphertext cc2, which corresponds to the difference between the TLWE ciphertext ca and the TLWE ciphertext cb, both use the entire range of the circle group {T} as the plaintext range. Therefore, the cryptographic processing device 1 performs a process of reducing the range of the plaintexts of the TLWE ciphertext cc1 and the TLWE ciphertext cc2 to the right half plane of the circular group {T}. The cryptographic processing device 1 (first bootstrap unit 17) performs first bootstrap on either the TLWE ciphertext cc1 or the TLWE ciphertext cc2 using a flat first test vector polynomial with all coefficients of 1 / 4 to obtain a TLWE ciphertext cd. This TLWE ciphertext cd is a ciphertext that indicates whether the TLWE ciphertexts cc1 and cc2 have plaintext on the right half or the left half, as described above in FDFB. The TLWE ciphertext cd can be calculated based on only one of the TLWE ciphertexts cc1 and cc2. The cryptographic processing device 1 (third arithmetic unit 14) performs a third homomorphic operation of homomorphically adding the TLWE ciphertext cd to the TLWE ciphertext cc1 to obtain a new TLWE ciphertext cc1' as described in FIG. 8(a). The cryptographic processing device 1 (fourth arithmetic unit 15) performs a fourth homomorphic operation of homomorphically adding the TLWE ciphertext cd to the TLWE ciphertext cc2 to obtain a new TLWE ciphertext cc2' which will be described in FIG. 8(b). As described above, the TLWE ciphertext cd is a ciphertext that has 1 / 4 as plaintext if the plaintext is on the right half plane, and has -1 / 4 as plaintext if the plaintext is on the left half plane. The first test vector polynomial may be constructed so that the TLWE ciphertext cd is a ciphertext that has -1 / 4 as plaintext if the plaintext is on the right half plane, and has 1 / 4 as plaintext if the plaintext is on the left half plane. In this case, the TLWE ciphertext cd may be homomorphically subtracted from the TLWE ciphertext cc1 or TLWE ciphertext cc2 to obtain the TLWE ciphertext cc1' or TLWE ciphertext cc2'. The same applies to the following cases. From the above, u'' = u + u' = u-u', and the plaintext of the TLWE ciphertext cd simultaneously satisfies u'' + 1 / 4 = u + u' + 1 / 4 = u-u' + 1 / 4. Therefore, the TLWE ciphertext cc1' is (a+b) / (4t)+1 / (8t)+u+u'+(u+u'+1 / 4)-(0,1 / 4) =(a+b) / (4t)+1 / (8t)+u+u'+(u-u'+1 / 4)-(0,1 / 4) =(a+b) / (4t)+1 / (8t)+u+u+1 / 4-(0,1 / 4) =(a+b) / (4t)+1 / (8t) Therefore, we have (a+b) / (4t)+1 / (8t) as the plaintext. u+u is either 0 or 1, and both are 0 on the circular group. And the TLWE ciphertext cc2' is (ab) / (4t)+1 / (8t)+u-u'+(u-u'+1 / 4)-(0,1 / 4) =(ab) / (4t)+1 / (8t)+u-u'+(u+u'+1 / 4)-(0,1 / 4) =(ab) / (4t)+1 / (8t)+u+u+1 / 4-(0,1 / 4) =(ab) / (4t)+1 / (8t) Therefore, we have (ab) / (4t)+1 / (8t) as the plaintext. u+u is either 0 or 1, and both are 0 on the circular group.
[0075] FIG. 8 is a diagram for explaining a ciphertext in which the range of a plaintext is reduced. As shown in Figure 8(a), the TLWE ciphertext cc1' is a ciphertext in which the range of the ciphertext cc1 for the sum of the TLWE ciphertext ca and TLWE ciphertext cb, which used the entire surface of the circular group {T}, is reduced to the right half surface of the circular group {T}. The addition result of the TLWE ciphertext ca and the TLWE ciphertext cb, whose plaintext integers can range from 0 to 7, never produces a negative value. Therefore, the TLWE ciphertext cc1 corresponding to the addition result can have any plaintext integer value from 0 to 14. Therefore, as shown in Fig. 8(a), in the TLWE ciphertext cc1', plaintext integers from 0 to 14 are assigned to the region (slice) from 0 / (4t) to 14 / (4t) in the right half of the circular group. The region from 15 / (4t) is not used. To calculate TLWE ciphertext cc1', the TLWE ciphertext ca and TLWE ciphertext cb are added, and the range of the ciphertext is reduced to the right half plane, halving the width of the slice. Therefore, the width of one slice in the circle group {T} corresponding to TLWE ciphertext cc1' is 1 / (4t), half of 1 / (2t) of the TLWE ciphertext ca and TLWE ciphertext cb. As shown in Figure 8(b), the TLWE ciphertext cc2' is a ciphertext in which the range of the ciphertext cc2, which is the difference between the TLWE ciphertext ca and the TLWE ciphertext cb that used the entire surface of the circular group {T}, is reduced to the right half surface of the circular group {T}. A negative value can occur as a result of subtracting the TLWE ciphertext ca from the TLWE ciphertext cb, whose plaintext integers can range from 0 to 7. Therefore, the TLWE ciphertext cc2 corresponding to the subtraction result can range from -7 to -1, or 0 to 7 as a plaintext integer. Therefore, as shown in FIG. 8(b), in the TLWE ciphertext cc2′, plaintext integers from −7 to 7 are assigned to the area from 0 / (4t) to 15 / (4t) in the right half of the circular group. To calculate TLWE ciphertext cc2', the difference between TLWE ciphertext ca and TLWE ciphertext cb is calculated, and the range of the ciphertext is reduced to the right half plane to halve the width of the slice. Therefore, the width of one slice in the circle group {T} corresponding to TLWE ciphertext cc2' is 1 / (4t), half of 1 / (2t) of TLWE ciphertext ca and TLWE ciphertext cb. However, when reducing to the right half plane, the entire range of the circular group, 0 to 1, is reduced to the range of 0 to 0.5 on the right half plane without changing the order, so the values 0 to 0.5 on the circular group of the TLWE ciphertext cc2 (which correspond to 0 to 7 in plaintext integers) are reduced to the range of 0 to 0.25 in the TLWE ciphertext cc2'. Similarly, the values 0.5 to 1 on the circular group of the TLWE ciphertext cc2 (which correspond to -8 to -1 in plaintext integers) are reduced to the range of 0.25 to 0.5 in the TLWE ciphertext cc2'. Therefore, in the TLWE ciphertext cc2', the values are arranged counterclockwise from 0 on the circular group in the order 0, 1, 2, 3, 4, 5, 6, 7, -8, -7, -6, -5, -4, -3, -2, -1. By calculating the TLWE ciphertext cc1' and TLWE ciphertext cc2' through the above process, the ciphertexts corresponding to (a+b) and (ab) are calculated. The number of BlindRotates required for this is only one time, which was required when calculating the TLWE ciphertext cd using the first test vector polynomial.
[0076] In FIG. 2B, the cryptographic processing device 1 calculates (a+b) 2 / 4 and (ab) 2 Obtain the ciphertext corresponding to each of / 4. Calculate the quotient by dividing the square of (a+b) by 4 and truncating the remainder, then calculate the quotient by dividing the square of (ab) by 4 and truncating the remainder. The cryptographic processing device 1 (the second bootstrap unit 18) performs the following on the TLWE ciphertext cc1': Second test vector polynomial T p (X) Perform the second Bootstrapping (Functional Bootstrapping) using TIFF0007681926000035.tif20109. Second test vector polynomial T p The calculated values of the (X) coefficients are stored in a LUT, and the calculated values stored in the LUT are referenced by BlindRotate. As a result, the cryptographic processing device 1 Obtain a TLWE ciphertext cf1 having TIFF0007681926000036.tif2023 as plaintext.
[0077] The cryptographic processing device 1 (third bootstrap unit 19) also calculates the third test vector polynomial T m (X) Perform the third Bootstrapping (Functional Bootstrapping) using TIFF0007681926000037.tif11108. The third test vector polynomial T m The calculated values of the (X) coefficients are stored in a LUT, and the calculated values stored in the LUT are referenced by BlindRotate. As a result, the cryptographic processing device 1 Obtain a TLWE ciphertext cf2 having TIFF0007681926000038.tif2022 as plaintext. This gives us (a+b) 2 TLWE ciphertext cf1 corresponding to / 4, (ab) 2 The TLWE ciphertext cf2 corresponding to / 4 is obtained. In the above, the order of the test vector polynomials T p (X), T m (X) is used. However, essentially, the test vector polynomial T p (X) is TIFF0007681926000039.tif1526 has the value (integer symbol value) as the numerator TIFF0007681926000040.tif2023 (where t is the number of divisions) The coefficients are the test vector polynomial T m (X) is It has the value TIFF0007681926000041.tif1524 (integer symbol value) as the numerator The coefficient is TIFF0007681926000042.tif2021. Since BlindRotate is performed to refer to the LUT once each in the cases of sum and difference, the number of times BlindRotate was required to calculate the TLWE ciphertext cf1 and the TLWE ciphertext cf2 was two.
[0078] In FIG. 2C, the cryptographic processing device 1 calculates (a+b) 2 / 4-(ab) 2 / 4, i.e., the ciphertext corresponding to the multiplication result is obtained. The cryptographic processing device 1 (fifth arithmetic unit 16) performs homomorphic subtraction of the TLWE ciphertext cf2 from the TLWE ciphertext cf1 to obtain a TLWE ciphertext cg. Homomorphic subtraction of TLWE ciphertext cf2 from TLWE ciphertext cf1 means that, between plaintexts, Corresponds to calculating TIFF0007681926000043.tif2046. In plaintext-to-plaintext operations, The result is TIFF0007681926000044.tif1196. The TLWE ciphertext cg is ab / 2t as plaintext. 2 and the multiplication result is obtained. The cryptographic processing device 1 was able to calculate the ciphertext of the multiplication result with three BlindRotates. Compared to the four times required when simply performing FDBD twice as described above, this is one less BlindRotate.
[0079] [Second Example] In the first embodiment, the multiplication result obtained as the TLWE ciphertext cg is a plaintext whose denominator is 2t 2 This differs from the plaintext denominator 2t in the TLWE ciphertexts ca and cb of the multiplier and multiplicand. Such a TLWE ciphertext cg cannot be used in subsequent multiplications with other ciphertexts whose plaintext denominator is 2t. In the second embodiment, the cryptographic processing device 1 decomposes the ciphertext of the multiplication result into lower bits and higher bits. More specifically, the cryptographic processing device 1 in the second embodiment calculates the ciphertext of the higher bits and the ciphertext of the lower bits of the multiplication result, respectively. The lower and upper bits of the multiplication result refer to a certain number of lower bits and the remaining bits when the multiplication result is expressed in binary. This is the expression when t is a power of 2, and even if the value is different, the expression is different and the meaning does not change essentially. The lower bits are the remainder when the multiplication result (ab) is divided by t, and the upper bits are the quotient when the multiplication result (ab) is divided by t.
[0080] FIG. 9 is a diagram illustrating the functional configuration of a cryptographic processing device according to a second embodiment of the present invention. FIG. 10 is a diagram for explaining a calculation process based on the functional configuration of FIG. The [second embodiment] shown in Figures 9 and 10 differs from the [first embodiment] in Figures 1 and 2 in that an eighth calculation unit 43, a ninth calculation unit 44, a fourth calculation unit 51, and a fifth calculation unit 52 are provided instead of the second calculation unit 18, the third calculation unit 19, and the fifth calculation unit 16.
[0081] The process of calculating the TLWE ciphertext cc1' and the TLWE ciphertext cc2' (A) is the same as in the first embodiment. In the process of (B), the cryptographic processing device 1 calculates (a+b) 2 TLWE ciphertext corresponding to / 4, (ab) 2 In order to obtain the TLWE ciphertext corresponding to / 4, the contents of the LUT are decomposed in advance into a LUT for the lower bits and a LUT for the upper bits. The cryptographic processing device 1 uses the many LUT technique to refer to the LUT for lower bits and the LUT for higher bits in one BlindRotate. This makes it possible to calculate the ciphertext of the higher bits and the ciphertext of the lower bits of the multiplication result without increasing the number of BlindRotates. Note that many LUT is a process of performing BlindRotate for different test vector polynomials (referring to different LUTs) using a common TLWE ciphertext. The cryptographic processing device 1 calculates (a+b) 2 / 4 corresponds to the lower bits of the multiplication result of a and b TIFF0007681926000045.tif2036 is the fourth test vector polynomial T p1 The coefficient is the odd-order term in (X), and the calculated value of the coefficient is stored in advance in the LUT for odd orders (lower bits). TIFF0007681926000046.tif2038 is (a+b) 2 / 4 divided by t is the remainder (a+b) 2 Corresponds to the lower bits of / 4. The cryptographic processing device 1 also calculates (a+b) 2 / 4 corresponds to the upper bits of the multiplication result of a and b TIFF0007681926000047.tif2526 is the fourth test vector polynomial T p1The coefficient is set as the coefficient of the even-order term in (X), and the calculated value of the coefficient is stored in advance in the LUT for even orders (higher bits). TIFF0007681926000048.tif2527 is (a+b) 2 / 4 divided by t is (a+b) 2 Corresponds to the upper bits of / 4.
[0082] In addition, the cryptographic processing device 1 includes: 2 / 4 corresponds to the lower bits of the multiplication result of a and b TIFF0007681926000049.tif2039 is the fifth test vector polynomial T m1 The coefficient is the odd-order term in (X), and the calculated value is stored in advance in the LUT for the lower bits. TIFF0007681926000050.tif2039 is (ab) 2 / 4 divided by t is the remainder (ab) 2 Corresponds to the lower bits of / 4. The cryptographic processing device 1 also includes: 2 / 4 corresponds to the upper bits of the multiplication result of a and b TIFF0007681926000051.tif2527 is the fifth test vector polynomial T m1 The coefficient is the even-numbered term in (X), and the calculated value is stored in advance in the LUT for the higher bits. TIFF0007681926000052.tif2526 is (ab) 2 / 4 divided by t, (ab) 2 Corresponds to the upper bits of / 4. Conversely, the test vector polynomial T p1 (X), test vector polynomial T m1 Let the even coefficients in (X) be (a+b). 2 / 4, (ab) 2 Alternatively, the even-order coefficients may correspond to the most significant bits of / 4, and the odd-order coefficients may correspond to the most significant bits. However, in this embodiment, the even-order coefficients are explained as corresponding to the most significant bits, and the odd-order coefficients are explained as corresponding to the least significant bits.
[0083] The cryptographic processing device 1 (fourth bootstrap unit 51) performs the above test vector polynomial T p1 Perform the fourth Bootstrapping (Functional Bootstrapping) using (X). At this time, the cryptographic processing device 1 can simultaneously refer to the LUT for the higher order bits (even order) and the LUT for the lower order bits (odd order) by using many LUTs. Here, since the result of squaring any integer is always non-negative and t is a positive value, the sign does not change due to division by 4 or t, floor functions, or modulus calculations. Therefore, the fourth test vector polynomial T p1 All coefficients of (X) TIFF0007681926000053.tif2525 and TIFF0007681926000054.tif2039 is necessarily non-negative and has a numerator less than t, so it only uses the right half-plane of the cycle group {T}. The cryptographic processing device 1 obtains the TLWE ciphertext c PU And the TLWE ciphertext c of the odd side (lower bits = remainder) PL And, you get.
[0084] The cryptographic processing device 1 (the fifth bootstrap unit 52) performs a fifth test vector polynomial T m1 Then, the cryptographic processing device 1 performs a fifth Bootstrapping (Functional Bootstrapping) using (X). At this time, the cryptographic processing device 1 can simultaneously refer to the LUT for the higher-order bits and the LUT for the lower-order bits by using many LUTs.
[0085] Here, since the result of squaring any integer is always non-negative and t is a positive value, the sign does not change due to division by 4 or t, floor functions, or modulus calculations. Therefore, the test vector polynomial T m1 All coefficients of (X) TIFF0007681926000055.tif2527 and Since TIFF0007681926000056.tif2038 is always non-negative and since it is divided by t, the numerator is always less than t, so only the right half-plane of the cycle group {T} is used. As a result of the fifth Bootstrapping using the many LUTs on the TLWE ciphertext cc2′, the cryptographic processing device 1 obtains the TLWE ciphertext c MU And the odd side (lower bits = remainder) is TLWE ciphertext c ML And, you get.
[0086] Regarding (C), the test vector polynomial T p1 (X) and the test vector polynomial T m1 The coefficient of (X) is (a+b) 2 / 4, (ab) 2 / 4 is decomposed into the quotient and remainder when divided by t. Therefore, (a+b) 2 In the second embodiment, the ciphertext of / 4 is the TLWE ciphertext of the quotient c PU , the remainder TLWE ciphertext c PL It is decomposed into: Also (ab) 2 In the second embodiment, the ciphertext of / 4 is the TLWE ciphertext of the quotient c MU , the remainder TLWE ciphertext c ML It is decomposed into: Therefore, the TLWE ciphertext c PU and TLWE ciphertext c PL For t×c PU +c PL The result is the plaintext of the ciphertext cf1 in the first embodiment. Matches TIFF0007681926000057.tif2024. Also, the TLWE ciphertext c MU and TLWE ciphertext c ML For t×c MU +c ML The result is the plaintext of the ciphertext cf2 in the first embodiment. Matches TIFF0007681926000058.tif2023.
[0087] The cryptographic processing device 1 (the eighth calculation unit 43) calculates (a+b) 2 TLWE ciphertext c corresponding to the quotient of / 4 PU From, (ab) 2 TLWE ciphertext c corresponding to the quotient of / 4 MU homomorphic subtraction (c PU -c MU ) and the TLWE ciphertext c corresponding to the most significant bits of the multiplication result U get. Furthermore, the cryptographic processing device 1 (the ninth calculation unit 44) calculates (a+b) 2 TLWE ciphertext c corresponding to the remainder of / 4 PL From (ab) 2 TLWE ciphertext c corresponding to the remainder of / 4 ML homomorphic subtraction (c PL -c ML ) and the TLWE ciphertext c corresponding to the lower bits of the multiplication result L get. Now, if we calculate the plaintext by combining the upper and lower bits, we get φ(t×c U +c L )=φ(t×(c PU -c MU )+(c PL -c ML ))=φ((t×c PU +c PL )-(t×c MU +c ML ))=φ(t×c PU +c PL )-φ(t×c MU -c ML ), so It can be confirmed that the file is TIFF0007681926000059.tif1196. Here, φ is the decryption function, and the value obtained by φ() is the plaintext of the ciphertext. Therefore, the TLWE ciphertext c U and TLWE ciphertext c L has the plaintext values obtained by decomposing the calculation result of ab / 2t into high-order bits and low-order bits.
[0088] TLWE ciphertext c U and TLWE ciphertext c L is the ciphertext that becomes the most significant bit and least significant bit of the multiplication result, but since the plaintext has a denominator of 2t, it can be used in subsequent multiplications with other ciphertexts whose plaintext has a denominator of 2t. The above gives us the ciphertext c, which corresponds to the most significant bit of the multiplication result of plaintext a and plaintext b. U , the ciphertext c corresponding to the lower bits L were obtained, respectively.
[0089] As mentioned above, the result of referencing each LUT is only the right half of the circle group, so the difference, the TLWE ciphertext c U and TLWE ciphertext c L In both cases, it can be confirmed that the plaintext does not extend beyond the entire circle group, and no information loss occurs. In addition, the TLWE ciphertext c L can be negative. For example, when a = 1, b = 6, and t = 8, the plaintext integer of the TLWE ciphertext cu is 1, and the plaintext integer of the TLWE ciphertext c is 0. L The plaintext integer of is -2. While 1×6=6 should be true, t×1-2=6 is true, so the calculation itself can be said to be correct. However, if a = 3, b = 2, and t = 8, the TLWE ciphertext c U The plaintext integer of is 0, and the TLWE ciphertext c L Compare this to the fact that the plaintext integer is 6, t × 0 + 6 = 6, so there are more than two possible representations for the same multiplication result, 6. Depending on the subsequent calculations, this may be fine, but depending on the application, additional normalization may be required. Normalization means that the calculation result for the result 6 in the above example is always expressed in the same way.
[0090] If normalization is required, the following process is added. First, the TLWE ciphertext c LTo determine whether t is negative or non-negative, i.e., whether the plaintext is in the right or left half plane of the circle group {T}, we use a flat test vector polynomial with all coefficients 1 / (4t) to test the TLWE ciphertext c L Bootstrap the above code to obtain the TLWE ciphertext cs. TLWE ciphertext cs is the TLWE ciphertext c L If the plaintext of lies on the left half-plane of the circle group {T}, then it has -1 / (4t) as plaintext, and if it lies on the right half-plane, then it has 1 / (4t) as plaintext. TLWE ciphertext cs'=cS-(0,1 / (4t)) TLWE ciphertext cs''=t×cs-(0,1 / 4) Calculate. The TLWE ciphertext cs' is an integer symbol, -1(TLWE ciphertext c L Since the plaintext of cs′ is negative (only when the plaintext of cs′ is negative) or 0, the cryptographic processing device 1 converts the TLWE ciphertext cs′ into the TLWE ciphertext c U Add homomorphically to . TLWE ciphertext cs'' is the TLWE ciphertext c L If the plaintext of is negative, the plaintext is -1 / 2, otherwise it is 0. Therefore, the cryptographic processing device 1 converts the TLWE ciphertext cs'' into the TLWE ciphertext c L Add (or subtract) homomorphically to . TLWE ciphertext c u The plaintext of is 1, and the TLWE ciphertext c L If the plaintext of cs is -2, the plaintext of the TLWE ciphertext cs is -1 / (4t), and the new TLWE ciphertext c u , a new TLWE ciphertext c with 6 as plaintext L is obtained.
[0091] [Third Example] In the first and second embodiments, the coefficients of the TLWE ciphertext ca and the TLWE ciphertext cb are divided by 2, and then addition and subtraction of the TLWE ciphertext ca' and the TLWE ciphertext cb' are performed. Alternatively, the TLWE ciphertext ca and the TLWE ciphertext cb may be added and subtracted first, and then divided by two. In this case, the cryptographic processing device 1 performs homomorphic addition (ca+cb) on the TLWE ciphertext ca and the TLWE ciphertext cb to obtain a new TLWE ciphertext. Also, the cryptographic processing device 1 performs homomorphic subtraction (ca-cb) of the TLWE ciphertext cb from the TLWE ciphertext ca to obtain a new TLWE ciphertext. The cryptographic processing device 1 obtains a TLWE ciphertext cc1 by dividing the coefficient of the ciphertext resulting from the homomorphic addition by 2. The cryptographic processing device 1 also obtains a TLWE ciphertext cc2 by dividing the coefficient of the ciphertext resulting from the homomorphic subtraction by 2. The subsequent processing using the TLWE ciphertexts cc1 and cc2 is the same as that shown in FIG. However, since the elements of the LWE ciphertexts of the sum and difference of the TLWE ciphertext ca and the TLWE ciphertext cb are no longer elements of the circle group, it is necessary to ensure that no information is lost. For example, a TLWE ciphertext ca having 0.6 on the circular group as a plaintext is multiplied by a TLWE ciphertext cb having 0.8 on the circular group as a plaintext. In this case, the sum of the TLWE ciphertext ca and the TLWE ciphertext cb is calculated in the same manner as in the first and second embodiments. In this case, when adding 0.6 + 0.8 and the plaintext, the correct result should be 1.4, or 0.4, in terms of operations on the circular group. However, when dividing the sum by 2, it is necessary to divide 1.4 by 2, because dividing 0.4 by 2 gives 0.2, which is not the correct value. Therefore, if the circle group is expressed as a fixed-point representation with an integer part of 0 bits and a decimal part of 32 bits, the sum and difference must be expressed with an integer part of 1 bit and a decimal part of 32 bits. This is disadvantageous when implementing on a CPU where the bit width of variables is fixed. It is also possible to allow error in the lowest digit and have an integer part of 1 bit and a decimal part of 31 bits. In this case, if the fixed-point representation of a 1-bit integer part and a 31-bit decimal part obtained as the result of the addition or subtraction is read as a fixed-point number with a 0-bit integer part and a 32-bit decimal part with the bit order unchanged, it will have the effect of performing a divide-by-2 operation after addition or subtraction.
[0092] FIG. 11 is a flowchart illustrating the multiplication process according to the first embodiment of this embodiment. In step S101, the cryptographic processing device 1 (sixth arithmetic unit 41) divides the coefficient of the TLWE ciphertext ca by 2 to obtain a TLWE ciphertext ca'. In step S102, the cryptographic processing device 1 (seventh arithmetic unit 42) divides the coefficient of the TLWE ciphertext cb by 2 to obtain a new TLWE ciphertext cb'. The processes in steps S101 and S102 may be performed in any order. In step S103, the cryptographic processing device 1 (first arithmetic unit 12) performs homomorphic addition of the TLWE ciphertext ca' and the TLWE ciphertext cb' to obtain a new TLWE ciphertext cc1. In step S104, the cryptographic processing device 1 (second arithmetic unit 13) performs homomorphic subtraction of the TLWE ciphertext cb' from the TLWE ciphertext ca' to obtain a new TLWE ciphertext cc2. The processes in steps S103 and S104 may be performed in any order.
[0093] In relation to the third embodiment, the processes corresponding to steps S101 and S102 may be performed after the processes corresponding to steps S103 and S104. That is, the TLWE ciphertext ca and the TLWE ciphertext cb may be homomorphically added, and the coefficient of the ciphertext resulting from the addition may be divided by 2 to obtain the TLWE ciphertext cc1. The TLWE ciphertext cb may be homomorphically subtracted from the TLWE ciphertext ca, and the coefficient of the resulting ciphertext may be divided by 2 to obtain the TLWE ciphertext cc2.
[0094] In step S105, the cryptographic processing device 1 (first bootstrap unit 17) performs first bootstrap on the TLWE ciphertext cc1 using a first test vector polynomial T1(X) whose coefficients are all flat and ¼, to obtain a new TLWE ciphertext cd. In step S106, the cryptographic processing device 1 (third arithmetic unit 14) performs homomorphic addition of the TLWE ciphertext cc1 and the TLWE ciphertext cd to obtain a new ciphertext cc1'. In step S107, the cryptographic processing device 1 (fourth arithmetic unit 15) performs homomorphic addition of the TLWE ciphertext cc2 and the TLWE ciphertext cd to obtain a new ciphertext cc2'. The processes in steps S106 and S107 may be performed in any order. In step S108, the cryptographic processing device 1 (the second bootstrap unit 18) calculates the second test vector polynomial T p A second bootstrap is performed using (X) to obtain a new TLWE ciphertext cf1. In step S109, the cryptographic processing device 1 (the third bootstrap unit 19) calculates the third test vector polynomial T m A third bootstrap is performed using (X) to obtain a new TLWE ciphertext cf2. The processes in steps S108 and S109 may be performed in any order. In step S110, the cryptographic processing device 1 (the fifth arithmetic unit 16) performs homomorphic subtraction of the TLWE ciphertext cf2 from the TLWE ciphertext cf1 to obtain a new TLWE ciphertext cg corresponding to the multiplication result. This TLWE ciphertext cg includes both the most significant bits and the least significant bits. Through the above process, we were able to obtain the multiplication result of integer-wise TLWE ciphertexts.
[0095] FIG. 12 is a flowchart illustrating the multiplication process according to the second embodiment of the present invention. Steps S201 to S207 are the same as steps S101 to S107 in FIG. In relation to the third embodiment, the processes corresponding to steps S201 and S202 may be performed after the processes corresponding to steps S203 and S204. That is, the TLWE ciphertext ca and the TLWE ciphertext cb may be homomorphically added, and the coefficient of the ciphertext resulting from the addition may be divided by 2 to obtain the TLWE ciphertext cc1. The TLWE ciphertext cb may be homomorphically subtracted from the TLWE ciphertext ca, and the coefficient of the resulting ciphertext may be divided by 2 to obtain the TLWE ciphertext cc2. In step S208, the cryptographic processing device 1 (the fourth bootstrap unit 51) calculates the fourth test vector polynomial T p1 The fourth bootstrap is performed using (X), and the new TLWE ciphertext c PU , c PL get. In step S209, the cryptographic processing device 1 (the fifth bootstrap unit 52) performs a fifth test vector polynomial T m The fifth bootstrap is performed using (X), and the new TLWE ciphertext c MU , c ML get. The processes in steps S208 and S209 may be performed in any order. In step S210, the cryptographic processing device 1 (the eighth calculation unit 43) PU From TLWE ciphertext c MU Subtract homomorphically from the new TLWE ciphertext c U We obtain the TLWE ciphertext c U is the ciphertext corresponding to the most significant bits of the multiplication result. In step S211, the cryptographic processing device 1 (the ninth calculation unit 44) PL From TLWE ciphertext c ML Subtract homomorphically from the new TLWE ciphertext c L We obtain the TLWE ciphertext c L is the ciphertext corresponding to the lower bits of the multiplication result. Through the above process, the most significant and least significant bits of the multiplication result of integer-wise TLWE ciphertexts can be obtained.
[0096] [Fourth Example] As shown in Figure 2(A), in [First embodiment], the coefficients of the TLWE ciphertext ca and the TLWE ciphertext cb are divided by 2 respectively to calculate the TLWE ciphertext ca' and the TLWE ciphertext cb', and then the TLWE ciphertext cc1' and the TLWE ciphertext cc2' are calculated by performing homomorphic addition and homomorphic subtraction between these ciphertexts. Alternatively, after calculating the TLWE ciphertext cc1' using the same procedure as in Figure 2(A), the TLWE ciphertext cc2' can be calculated by homomorphically subtracting the TLWE ciphertext cb from the TLWE ciphertext cc1'. Since the plaintext of the TLWE ciphertext cc1' is (a+b) / (4t)+1 / (8t) and the plaintext of the TLWE ciphertext cc2' is (ab) / (4t)+1 / (8t), (a+b) / (4t)+1 / (8t)-{(ab) / (4t)+1 / (8t)} =a / (4t)+b / (4t)+1 / (8t)-{a / (4t)-b / (4t)+1 / (8t)} =a / (4t)+b / (4t)+1 / (8t)-a / (4t)+b / (4t)-1 / (8t)=2b / (4t)=b / (2t) Therefore, ignoring the difference in offset, TLWE ciphertext cc1'-TLWE ciphertext cc2'=TLWE ciphertext cb. Therefore, the TLWE ciphertext cc2' can be obtained from the TLWE ciphertext cc1'-TLWE ciphertext cb. Specifically, the cryptographic processing device 1 calculates the TLWE ciphertext cc2' by performing a homomorphic operation to calculate cc1'-cb+(0,1 / (4t)). In this case, there is no need to perform the second homomorphic operation by the second operation unit 13 of homomorphically subtracting the TLWE ciphertext cb' from the TLWE ciphertext ca' in Fig. 2(A). As a result, there is no need to perform the fourth homomorphic operation by the fourth operation unit 15 of homomorphically adding the TLWE ciphertext cc2 and the TLWE ciphertext cd.
[0097] The details are explained below. As shown above, the plaintext of the TLWE ciphertext cc1' is (a+b) / (4t)+1 / (8t), and the plaintext of the TLWE ciphertext cb is b / (2t)+1 / (4t). Therefore, the plaintext of cc1'-cb+(0,1 / (4t)) is The following calculations: (a+b) / (4t)+1 / (8t)-{b / (2t)+1 / (4t)}+1 / (4t) =a / (4t)+b / (4t)+1 / (8t)-{b / (2t)+1 / (4t)}+1 / (4t) =a / (4t)+b / (4t)+1 / (8t)-2b / (4t)-1 / (4t)+1 / (4t) =a / (4t)+b / (4t)-2b / (4t)-1 / (4t)+1 / (4t)+1 / (8t) = a / (4t)-b / (4t)+1 / (8t) =(ab) / (4t)+1 / (8t) Therefore, (ab) / (4t)+1 / (8t). The plaintext of the TLWE ciphertext cc2' explained in the first embodiment was (ab) / (4t)+1 / (8t). From the above, it is clear that a ciphertext having the same plaintext as the TLWE ciphertext cc2' can be obtained by cc1'-cb+(0,1 / (4t)).
[0098] Also {(a+b) / (4t)+1 / (8t)}+{(ab) / (4t)+1 / (8t)} =a / (4t)+b / (4t)+1 / (8t)+a / (4t)-b / (4t)+1 / (8t) =2a / (4t)+2 / (8t)=a / (2t)+1 / (4t) Therefore, ignoring the difference in offset, TLWE ciphertext cc1' + TLWE ciphertext cc2' = TLWE ciphertext ca. Therefore, the TLWE ciphertext cc2' can be calculated by homomorphically subtracting the TLWE ciphertext ca from the TLWE ciphertext cc1'. Specifically, the cryptographic processing device 1 calculates the TLWE ciphertext cc2' by performing a homomorphic operation to calculate cc1'-ca+(0,1 / (4t)).
[0099] As shown above, the plaintext of the TLWE ciphertext cc1' is (a+b) / (4t)+1 / (8t), and the plaintext of the TLWE ciphertext ca is a / (2t)+1 / (4t). Therefore, the plaintext of cc1'-ca+(0,1 / (4t)) is The following calculations: (a+b) / (4t)+1 / (8t)-{a / (2t)+1 / (4t)}+1 / (4t) =a / (4t)+b / (4t)+1 / (8t)-{a / (2t)+1 / (4t)}+1 / (4t) =a / (4t)+b / (4t)+1 / (8t)-2a / (4t)-1 / (4t)+1 / (4t) =a / (4t)+b / (4t)-2a / (4t)-1 / (4t)+1 / (4t)+1 / (8t) =-a / (4t)+b / (4t)+1 / (8t) =(-a+b) / (4t)+1 / (8t) Therefore, (-a+b) / (4t)+1 / (8t). The plaintext of the TLWE ciphertext cc2' described in [First embodiment] was (ab) / (4t)+1 / (8t). From the above, the TLWE ciphertext cc2'' is obtained by inverting the sign of the integer symbol corresponding to the plaintext from the TLWE ciphertext cc2' by cc1'-ca+(0,1 / (4t)). The handling of the TLWE ciphertext cc2'' will be described later. Alternatively, by homomorphically subtracting the TLWE ciphertext cc1' from the TLWE ciphertext ca (ca-cc1'), the TLWE ciphertext cc2' can be calculated without calculating the TLWE ciphertext cc2''. In this case, it is not necessary to add an offset such as (0,1 / (4t)) to ca-cc1'.
[0100] FIG. 13 is a diagram illustrating the functional configuration of a cryptographic processing device according to a fourth embodiment of the present invention. FIG. 14 is a diagram for explaining a calculation process based on the functional configuration of FIG. The fourth embodiment shown in FIGS. 13 and 14 differs from the first embodiment shown in FIGS. 1 and 2 in that the fourth embodiment does not include the second arithmetic unit 13 and the fourth arithmetic unit 15, but includes a tenth arithmetic unit 45. In the fourth embodiment, ciphertexts corresponding to the sum (a+b) and difference (ab) of plaintext a and plaintext b are calculated as shown in FIG. In FIG. 14, the cryptographic processing device 1 inputs the TLWE ciphertext ca to a sixth arithmetic unit 41, and obtains a new TLWE ciphertext ca′ by dividing the coefficient of the TLWE ciphertext ca by two. Furthermore, the cryptographic processing device 1 inputs the TLWE ciphertext cb to a seventh arithmetic unit 42, and obtains a new TLWE ciphertext cb' by dividing the coefficient of the TLWE ciphertext cb by two. The cryptographic processing device 1 inputs the TLWE ciphertext ca' and the TLWE ciphertext cb' to the first arithmetic unit 12, and performs homomorphic addition (first homomorphic operation) between the TLWE ciphertext ca' and the TLWE ciphertext cb' to obtain a new TLWE ciphertext cc1. The cryptographic processing device 1 inputs the TLWE ciphertext cc1 to the first bootstrap unit 17, and performs gate bootstrap on the TLWE ciphertext cc1 using a flat test vector polynomial T1(X) whose all coefficients are 1 / 4, to obtain a new TLWE ciphertext cd.
[0101] The cryptographic processing device 1 inputs the TLWE ciphertext cc1 and the TLWE ciphertext cd to the third arithmetic unit 14, and performs homomorphic addition (third homomorphic operation) between the TLWE ciphertext cc1 and the TLWE ciphertext cd to obtain a new TLWE ciphertext cc1'.
[0102] A first test vector polynomial may be constructed so that the TLWE ciphertext cd has -1 / 4 as plaintext if the plaintext is on the right half of the plane, and has 1 / 4 as plaintext if the plaintext is on the left half of the plane, and the TLWE ciphertext cc1' may be obtained by homomorphically subtracting the TLWE ciphertext cd from the TLWE ciphertext cc1. The cryptographic processing device 1 inputs the TLWE ciphertext cc1' and the TLWE ciphertext cb to a tenth arithmetic unit 45, and performs homomorphic subtraction between the TLWE ciphertext cc1' and the TLWE ciphertext cb (tenth homomorphic operation) to obtain a new TLWE ciphertext cc2'. This tenth homomorphic operation is a homomorphic operation that calculates the above-mentioned cc1'-cb+(0,1 / (4t)). Alternatively, the cryptographic processing device 1 inputs the TLWE ciphertext cc1' and the TLWE ciphertext ca to the tenth arithmetic unit 45, and performs homomorphic subtraction between the TLWE ciphertext cc1' and the TLWE ciphertext ca as the tenth homomorphic operation to obtain a new TLWE ciphertext cc2'. In this case, the tenth homomorphic operation is a homomorphic operation that calculates the above-mentioned cc1'-ca+(0,1 / (4t)). The processing after calculating the TLWE ciphertext cc1' and the TLWE ciphertext cc2' is the same as that in FIG.
[0103] [Fifth Example] In the fourth embodiment, the TLWE ciphertext cc1' is calculated, and the TLWE ciphertext cb or the TLWE ciphertext ca is homomorphically subtracted from the calculated TLWE ciphertext cc1' to calculate the TLWE ciphertext cc2'. On the other hand, after calculating the TLWE ciphertext cc2' using the same procedure as in the case of Fig. 2(A), the TLWE ciphertext cc1' can be calculated by homomorphically adding the TLWE ciphertext cb to the TLWE ciphertext cc2'. This is because, as described in [Fourth embodiment], TLWE ciphertext cc1'-TLWE ciphertext cc2'=TLWE ciphertext cb holds. The TLWE ciphertext cc1' can be obtained from the TLWE ciphertext cc2'+TLWE ciphertext cb. Specifically, the cryptographic processing device 1 calculates the TLWE ciphertext cc1' by performing a homomorphic operation to calculate cc2'+cb-(0,1 / (4t)).
[0104] As shown above, the plaintext of the TLWE ciphertext cc2' is (ab) / (4t)+1 / (8t), and the plaintext of the TLWE ciphertext cb is b / (2t)+1 / (4t). Therefore, the plaintext of cc2'+cb-(0,1 / (4t)) is The following calculations: (ab) / (4t)+1 / (8t)+{b / (2t)+1 / (4t)}-1 / (4t) =a / (4t)-b / (4t)+1 / (8t)+{b / (2t)+1 / (4t)}-1 / (4t) =a / (4t)-b / (4t)+1 / (8t)+2b / (4t)+1 / (4t)-1 / (4t) =a / (4t)+b / (4t)+1 / (8t) Therefore, (a+b) / (4t)+1 / (8t). The plaintext of the TLWE ciphertext cc1' explained in the first embodiment was (a+b) / (4t)+1 / (8t). From the above, it is clear that a ciphertext having the same plaintext as the TLWE ciphertext cc1' can be obtained by cc2'+cb-(0,1 / (4t)).
[0105] In addition, the TLWE ciphertext cc1' can be calculated by homomorphically subtracting the TLWE ciphertext ca from the TLWE ciphertext cc2'. This is because, as described in the fourth embodiment, TLWE ciphertext cc1'+TLWE ciphertext cc2'=TLWE ciphertext ca holds true, and the TLWE ciphertext cc1' can be obtained from the TLWE ciphertext cc2'-TLWE ciphertext ca. Specifically, the cryptographic processing device 1 calculates the TLWE ciphertext cc1' by performing a homomorphic operation to calculate cc2'-ca+(0,1 / (4t)). As shown above, the plaintext of the TLWE ciphertext cc2' is (ab) / (4t)+1 / (8t), and the plaintext of the TLWE ciphertext ca is a / (2t)+1 / (4t). Therefore, the plaintext of cc2'-ca+(0,1 / (4t)) is The following calculations: (a+b) / (4t)+1 / (8t)-{a / (2t)+1 / (4t)}+1 / (4t) =a / (4t)+b / (4t)+1 / (8t)-{a / (2t)+1 / (4t)}+1 / (4t) =a / (4t)+b / (4t)+1 / (8t)-2a / (4t)-1 / (4t)+1 / (4t) =a / (4t)+b / (4t)-2a / (4t)-1 / (4t)+1 / (4t)+1 / (8t) =-a / (4t)+b / (4t)+1 / (8t) =(-a+b) / (4t)+1 / (8t) Therefore, (-a+b) / (4t)+1 / (8t). The plaintext of the TLWE ciphertext cc2' is (ab) / (4t)+1 / (8t). From the above, the TLWE ciphertext cc1'' is obtained by inverting the sign of the integer symbol corresponding to the plaintext by cc2'-ca+(0,1 / (4t)). The handling of the TLWE ciphertext cc1'' will be described later. Alternatively, by homomorphically subtracting the TLWE ciphertext cc2' from the TLWE ciphertext ca (ca-cc2'), the TLWE ciphertext cc1' can be calculated without calculating the TLWE ciphertext cc1''. In this case, it is not necessary to add an offset such as (0,1 / (4t)) to ca-cc2'.
[0106] FIG. 15 is a diagram for explaining the functional configuration of a cryptographic processing device according to a fifth embodiment of the present invention. FIG. 16 is a diagram for explaining a calculation process based on the functional configuration of FIG. The [fifth embodiment] shown in Figures 15 and 16 differs from the [fourth embodiment] in Figures 13 and 14 in that the fifth embodiment does not have a first calculation unit 12, a third calculation unit 14, and a tenth calculation unit 45, but has a second calculation unit 13, a fourth calculation unit 15, and an eleventh calculation unit 46. In the fifth embodiment, ciphertexts corresponding to the sum (a+b) and difference (ab) of plaintext a and plaintext b are calculated as shown in FIG. In FIG. 16, the cryptographic processing device 1 inputs the TLWE ciphertext ca to a sixth arithmetic unit 41, and obtains a new TLWE ciphertext ca′ by dividing the coefficient of the TLWE ciphertext ca by two. Furthermore, the cryptographic processing device 1 inputs the TLWE ciphertext cb to a seventh arithmetic unit 42, and obtains a new TLWE ciphertext cb' by dividing the coefficient of the TLWE ciphertext cb by two. The cryptographic processing device 1 inputs the TLWE ciphertext ca' and TLWE ciphertext cb' to the second arithmetic unit 13, and performs homomorphic subtraction (second homomorphic operation) between the TLWE ciphertext ca' and the TLWE ciphertext cb' to obtain a new TLWE ciphertext cc2. The cryptographic processing device 1 inputs the TLWE ciphertext cc2 to the first bootstrap unit 17, and performs gate bootstrap on the TLWE ciphertext cc2 using a flat test vector polynomial T1(X) whose all coefficients are 1 / 4, to obtain a new TLWE ciphertext cd.
[0107] The cryptographic processing device 1 inputs the TLWE ciphertext cc2 and the TLWE ciphertext cd to the fourth arithmetic unit 15, and performs homomorphic addition (fourth homomorphic operation) between the TLWE ciphertext cc2 and the TLWE ciphertext cd to obtain a new TLWE ciphertext cc2'. A first test vector polynomial may be constructed so that the TLWE ciphertext cd has -1 / 4 as plaintext if the plaintext is on the right half of the plane, and has 1 / 4 as plaintext if the plaintext is on the left half of the plane, and the TLWE ciphertext cc2' may be obtained by homomorphically subtracting the TLWE ciphertext cd from the TLWE ciphertext cc2. The cryptographic processing device 1 inputs the TLWE ciphertext cc2' and the TLWE ciphertext cb to an eleventh arithmetic unit 46, and performs homomorphic addition (eleventh homomorphic operation) between the TLWE ciphertext cc2' and the TLWE ciphertext cb to obtain a new TLWE ciphertext cc1'. This eleventh homomorphic operation is a homomorphic operation that calculates the above-mentioned cc2'+cb-(0,1 / (4t)). Alternatively, the cryptographic processing device 1 inputs the TLWE ciphertext cc2' and the TLWE ciphertext ca to the tenth arithmetic unit 45, and performs homomorphic subtraction between the TLWE ciphertext cc2' and the TLWE ciphertext ca as the eleventh homomorphic operation to obtain a new TLWE ciphertext cc1'. In this case, the eleventh homomorphic operation is a homomorphic operation that calculates the above-mentioned cc2'-ca+(0,1 / (4t)). The processes after the calculation of the TLWE ciphertext cc1' and the TLWE ciphertext cc2' are the same as those in FIG.
[0108] In addition, in the case of the [Second embodiment] described in Figures 9 and 10, the TLWE ciphertext cc1' and TLWE ciphertext cc2' can be calculated by performing the methods of the [Fourth embodiment] and [Fifth embodiment] in the process of Figure 10(A) which calculates ciphertexts corresponding to the sum (a+b) and difference (ab) of plaintext a and plaintext b, respectively. In this case, the cryptographic processing device 1 has a functional configuration including an eighth calculation unit 43, a ninth calculation unit 44, a fourth calculation unit 51, and a fifth calculation unit 52 in FIG. 9 instead of the second calculation unit 18 and the third calculation unit 19 in FIG. 13.
[0109] In addition, in [Example 3], to obtain the TLWE ciphertexts cc1 and cc2 of [Example 1] and [Example 2], homomorphic addition and homomorphic subtraction are performed on the TLWE ciphertext ca and the TLWE ciphertext cb, and the coefficients of the obtained ciphertexts are each divided by 2. In the fourth embodiment, in order to obtain the TLWE ciphertext cc1, homomorphic addition may be performed on the TLWE ciphertext ca and the TLWE ciphertext cb, and the coefficient of the obtained ciphertext may be divided by two. In this case, the cryptographic processing device 1 performs homomorphic addition of the TLWE ciphertext ca and the TLWE ciphertext cb to calculate a new TLWE ciphertext, and divides the coefficient of the obtained ciphertext by 2 to obtain the TLWE ciphertext cc1. The subsequent processing using the TLWE ciphertext cc1 and the TLWE ciphertext cc2 is the same as that in Figs. 2 and 10. In the fifth embodiment, the TLWE ciphertext cc2 may be obtained by performing homomorphic subtraction between the TLWE ciphertext ca and the TLWE ciphertext cb and dividing the coefficient of the obtained ciphertext by two. In this case, the cryptographic processing device 1 performs homomorphic subtraction between the TLWE ciphertext ca and the TLWE ciphertext cb to calculate a new TLWE ciphertext, and divides the coefficient of the obtained ciphertext by 2 to obtain the TLWE ciphertext cc2. The subsequent processing using the TLWE ciphertext cc1 and the TLWE ciphertext cc2 is the same as that in Figs. 2 and 10.
[0110] Note that, as described above, the TLWE ciphertext cc2’’ obtained in [Fourth Embodiment] and the TLWE ciphertext cc1’’ obtained in [Fifth Embodiment] have the signs (positive and negative) reversed from the TLWE ciphertext cc2’ and the TLWE ciphertext cc1’ as integer symbols. In FIGS. 2(B) and 10(B), the operation performed using the TLWE ciphertext cc1’ and the TLWE ciphertext cc2’ is a squaring operation, and x 2 = (-x) 2 Therefore, theoretically, the TLWE ciphertext cc2’’ and the TLWE ciphertext cc1’’ can also be used as they are. However, for example, it exceeds the value range of the LUT for squaring the TLWE ciphertext cc1’ of [Fifth Embodiment]. Therefore, it is necessary to change the test vector polynomial Tp(X) used for BlindRotate in the second Bootstrapping of [First Embodiment], or the test vector polynomial Tp1(X) used for BlindRotate in the fourth Bootstrapping of [Second Embodiment]. Therefore, it is desirable to reverse the signs of the TLWE ciphertext cc2’’ calculated in [Fourth Embodiment] and the TLWE ciphertext cc1’’ calculated in [Fifth Embodiment] again before the squaring calculation in FIGS. 2(B) and 10(B).
[0111] Hereinafter, a method for reversing the signs of the TLWE ciphertext cc2’’ and the TLWE ciphertext cc1’’ to obtain the TLWE ciphertext cc2’ and the TLWE ciphertext cc1’ will be described. Due to the influence of the offset, although the signs of the TLWE ciphertext cc2’’ and the TLWE ciphertext cc1’’ are reversed from the TLWE ciphertext cc2’ and the TLWE ciphertext cc1’ as integer symbols, they are not completely reversed on the circular group. Therefore, first, subtract the offset (0, 1 / (8t)) from the TLWE ciphertext cc2’’ and the TLWE ciphertext cc1’’ to remove the offset, reverse the signs of all coefficients of the ciphertext, and then add (0, 1 / (8t)) to give the offset. As a result, the TLWE ciphertext cc2’ and the TLWE ciphertext cc1’ with the signs of the integer symbols of the TLWE ciphertext cc2’’ and the TLWE ciphertext cc1’’ reversed are obtained. This makes it possible to perform bootstrap using the same test vector polynomials Tp(X) and Tp1(X) as in Figures 2(B) and 10(B) and calculate the squares of the TLWE ciphertexts cc2' and cc1'.
[0112] The calculation for obtaining the TLWE ciphertext cc2' and the TLWE ciphertext cc1' from the TLWE ciphertext cc2'' and the TLWE ciphertext cc1'' is expressed as follows. Let the TLWE ciphertext cc2'' and TLWE ciphertext cc1'' be the TLWE ciphertext ct. Let the TLWE ciphertext cc2' and TLWE ciphertext cc1' to be obtained be the TLWE ciphertext ct'. Calculate c1=ct-(0,1 / (8t)) to remove the offset of the TLWE ciphertext ct. Calculate c2 = -c1 and invert the sign of the TLWE ciphertext ct with the offset removed on the circular group. Calculate ct'=c2+(0,1 / (8t)) and add an offset again to obtain the TLWE ciphertext ct'. The above calculation can be summarized as ct' = -(ct - (0,1 / (8t)) + (0,1 / (8t)), which can be further simplified as ct' = -ct + (0,1 / (4t)). In the tenth homomorphic operation of [Fourth embodiment], by setting -{cc1'-ca+(0,1 / (4t))}+(0,1 / (4t)), it is possible to calculate the TLWE ciphertext cc2' without calculating the TLWE ciphertext cc2''. That is, -{cc1'-ca+(0,1 / (4t))}+(0,1 / (4t)) =-cc1'+ca-(0,1 / (4t))+(0,1 / (4t) =-cc1'+ca =-{(a+b) / (4t)+1 / (8t)}+a / (2t)+1 / (4t) =-(a+b) / (4t)-1 / (8t)+a / (2t)+1 / (4t) =-a / (4t)-b / (4t)-1 / (8t)+a / (2t)+1 / (4t) =-a / (4t)+a / (2t)-b / (4t)-1 / (8t)+1 / (4t) =-a / (4t)+2a / (4t)-b / (4t)-1 / (8t)+2 / (8t) = a / (4t)-b / (4t)+1 / (8t) =(ab) / (4t)+1 / (8t) The plaintext of the TLWE ciphertext cc2' is (ab) / (4t)+1 / (8t), and the above calculation shows that the TLWE ciphertext cc2' can be obtained by inverting the sign of the TLWE ciphertext cc2''.
[0113] In addition, in the 11th homomorphic operation of [Fifth embodiment], by setting -{cc2'-ca+(0,1 / (4t))}+(0,1 / (4t)), it is possible to calculate the TLWE ciphertext cc1' without calculating the TLWE ciphertext cc1''. That is, -{cc2'-ca+(0,1 / (4t))}+(0,1 / (4t)) =-cc2'+ca-(0,1 / (4t))+(0,1 / (4t) =-cc2'+ca =-{(ab) / (4t)+1 / (8t)}+a / (2t)+1 / (4t) =-(ab) / (4t)-1 / (8t)+a / (2t)+1 / (4t) =-a / (4t)+b / (4t)-1 / (8t)+a / (2t)+1 / (4t) =-a / (4t)+a / (2t)+b / (4t)-1 / (8t)+1 / (4t) =-a / (4t)+2a / (4t)+b / (4t)-1 / (8t)+2 / (8t) =a / (4t)+b / (4t)+1 / (8t)=(a+b) / (4t)+1 / (8t) The plaintext of the TLWE ciphertext cc1' is (a+b) / (4t)+1 / (8t), and the above calculation shows that the TLWE ciphertext cc1' can be obtained by inverting the sign of the TLWE ciphertext cc1''. The TLWE ciphertext cc1' calculated in [Example 4] and the TLWE ciphertext cc2' calculated in [Example 5] can also have their signs inverted to (ba) / (4t)+1 / (8t) or -(a+b) / (4t)+1 / (8t) as necessary by using the formula ct'=-ct+(0,1 / (4t)).
[0114] Multiplication is commutative, i.e., a×b=b×a. Therefore, even if the plaintexts of the TLWE ciphertext ca and the TLWE ciphertext cb are interchanged in the above-described [First embodiment], [Second embodiment], [Third embodiment], [Fourth embodiment], and [Fifth embodiment], the multiplication results in a ciphertext having the same plaintext.
[0115] FIG. 17 is a diagram showing ciphertexts input and output to and from Gate Bootstrapping of this embodiment. In the above description, it has been described that Gate Bootstrapping is performed in the order of BlindRotate, SampleExtract, and Public Key Switching, particularly in the first Bootstrapping, as shown in FIG. 17(a). Alternatively, as shown in FIG. 17(b), Public Key Switching can be executed first in Gate Bootstrapping, and then BlindRotate and SampleExtract can be executed. TLWE ciphertext has a concept of levels according to security strength. In Gate Bootstrapping in Fig. 17(a), the input and output TLWE ciphertexts are LEVEL 0. When BlindRotate is performed on the LEVEL 0 TLWE ciphertext and SampleExtract is performed on the output TRLWE ciphertext, the TLWE ciphertext obtained is LEVEL 1, but as a result of Public Key Switching, a LEVEL 0 TLWE ciphertext is output. In contrast, in the method shown in Figure 17(b), the TLWE ciphertext that is the input and output of Gate Bootstrapping is set to LEVEL 1, and first Public Key Switching is performed to lower it to LEVEL 0, and then BlindRotate is performed. When SampleExtract is performed on the output TRLWE ciphertext, a TLWE ciphertext of LEVEL 1 is output.
[0116] The ciphertext of LEVEL0 consists of an N-order vector [a] of elements on the circular group {T} encrypted with an N-order secret key [s]. On the other hand, the ciphertext of LEVEL1 obtained as a result of SampleExtract consists of an n-order vector [a'] of elements on the circular group {T} encrypted with an n-order secret key [s']. The LEVEL0 ciphertext has a smaller number of coefficients (the degree of the vector), which is the difficulty of the LWE problem, than the LEVEL1 ciphertext, so the amount of computation required for homomorphic addition is smaller than that of LEVEL1. On the other hand, the problem with LEVEL0 ciphertext is that the security strength is likely to decrease if the allowable error added to the plaintext is reduced, because the security of LWE-based ciphers is guaranteed by the error added to the plaintext. The larger the error added to the plaintext and the greater the number of coefficients (the degree of the vector), the more difficult it becomes to calculate (decrypt) the TLWE cipher. On the other hand, the smaller the error added to the plaintext and the fewer the number of coefficients (the degree of the vector), the easier it is to calculate (decrypt) the TLWE cipher. In particular, in the case of TFHE applied to the integer-wise type, the larger the plaintext (integer) value stored in the TLWE ciphertext becomes, the more finely it is necessary to divide the range of values from 0 to 1 in the circular group {T}, and there is also the problem of errors during decryption, which will be described later, so the error needs to be reduced. In that case, as mentioned above, the security strength is likely to decrease, so in order to reduce the error, it is necessary to ensure security by increasing the number of coefficients in the ciphertext (the degree of the vector).
[0117] In order to ensure the security of ciphertexts that are easier to calculate (decrypt) by reducing the error added to the plaintext, it is desirable to move Public Key Switching to the beginning of Gate Bootstrapping and use LEVEL1 ciphertexts, which have a large number of coefficients (vector order) and are therefore easier to reduce the error range, as the input and output of Gate Bootstrapping. Then, after converting to LEVEL0 at the beginning of Gate Bootstrapping, the ciphertext is not returned to LEVEL0 at the end. By not returning to LEVEL0, the calculation of the TLWE ciphertext can be performed safely in the next stage as well. The time required for BlindRotate is proportional to the number of coefficients (vector degree) of the input TLWE ciphertext, because the number of CMux is the same as the degree. Therefore, when the ciphertext of LEVEL1 is input, the time required for BlindRotate is longer in proportion to the number of coefficients (vector degree) than when the ciphertext of LEVEL0 is input. Even if the LEVEL1 ciphertext is used as the input for Gate Bootstrapping to ensure the security of the ciphertext, the increase in the required time can be avoided by performing BlindRotate using the LEVEL0 TLWE ciphertext converted by Public Key Switching as the input.
[0118] Furthermore, reducing the error added to the plaintext poses the problem of errors during decryption in addition to the security strength mentioned above. As described above, in TFHE applied to the integer-wise type, the range of values from 0 to 1 corresponding to the circular group {T} is divided into 2t parts. By increasing the value of t and dividing the circular group into smaller parts, the upper limit of the integer value that can be recorded in the TLWE ciphertext can be increased. The maximum value that can be stored is determined by the number of parts t into which the circular group is divided, but when trying to store a large value, the error range must be made smaller, which can lead to problems such as a decrease in security strength and an increase in the decryption error rate. In homomorphic encryption of the LWE system, including TFHE, the errors added to the plaintext are normally distributed, and it is not possible to strictly set the "error range." Although the error still tends to be concentrated near 0, in principle, this simply makes it possible to concentrate the error more in the specified range. If the error falls outside the set range, the plaintext will be interpreted as a value from a different divided domain, which may result in unexpected calculation results. The calculation itself does not become impossible, but rather a different result is obtained. How much of a probability of obtaining a different calculation result can be tolerated is up to the application to which homomorphic encryption is applied.
[0119] In order to best balance the three goals of reducing the probability of errors occurring in calculations, reducing the number of BlindRotates to speed up calculations, and maintaining high security, it is necessary to set the system parameters so that the overlap of the error ranges falls within a certain value. The error may be set so as to satisfy conditions that are of particular importance depending on the system or device to which this embodiment is applied. [Application example] The processing performed by the cryptographic processing device 1 can be applied as follows. For example, consider a case where you want to aggregate data for a specific field within a certain range from a database where the fields and records are encrypted with TLWE encryption (for example, you want to find the average annual income of people aged 30 to 39). In this case, the cryptographic processing device 1 is a database server that manages an encrypted database, accepts queries encrypted with TLWE encryption from a terminal device connected via a network, etc., and returns a response to the query to the terminal device in a state encrypted with TLWE encryption. Indexes cannot be created on encrypted databases, so comparisons and aggregations across the entire database are required.
[0120] The cryptographic processing device 1 performs a comparison operation to compare all records in the encrypted database with the query using the functions of the first calculation unit 12, the second calculation unit 13, the third calculation unit 14, the fourth calculation unit 15, the fifth calculation unit 16, the sixth calculation unit 41, the seventh calculation unit 42, the first bootstrap unit 17, the second bootstrap unit 18, and the third bootstrap unit 19. In addition, a comparison operation is performed to compare all records in the encrypted database with the query using the functions of the first calculation unit 12, the second calculation unit 13, the third calculation unit 14, the fourth calculation unit 15, the sixth calculation unit 41, the seventh calculation unit 42, the eighth calculation unit 43, the ninth calculation unit 44, the first bootstrap unit 17, the fourth bootstrap unit 51, and the fifth bootstrap unit 52. In addition, a comparison operation is performed to compare all records in the encrypted database with the query using the functions of the first calculation unit 12, the third calculation unit 14, the fifth calculation unit 16, the sixth calculation unit 41, the seventh calculation unit 42, the tenth calculation unit 45, the first bootstrap unit 17, the second bootstrap unit 18, and the third bootstrap unit 19. In addition, a comparison operation is performed to compare all records in the encrypted database with the query using the functions of the first calculation unit 12, the third calculation unit 14, the sixth calculation unit 41, the seventh calculation unit 42, the eighth calculation unit 43, the ninth calculation unit 44, the tenth calculation unit 45, the first bootstrap unit 17, the fourth bootstrap unit 51, and the fifth bootstrap unit 52. In addition, a comparison operation is performed to compare all records in the encrypted database with the query using the functions of the second calculation unit 13, the fourth calculation unit 15, the fifth calculation unit 16, the sixth calculation unit 41, the seventh calculation unit 42, the eleventh calculation unit 46, the first bootstrap unit 17, the second bootstrap unit 18, and the third bootstrap unit 19. Also, by the functions of the second arithmetic unit 13, the fourth arithmetic unit 15, the sixth arithmetic unit 41, the seventh arithmetic unit 42, the eighth arithmetic unit 43, the ninth arithmetic unit 44, the eleventh arithmetic unit 46, the first Bootstrapping unit 17, the fourth Bootstrapping unit 51, and the fifth Bootstrapping unit 52, a comparison operation is performed to compare all records of the encrypted database with the query. The comparison operation is to perform subtraction between the ciphertexts of the record and the query, and the sign of the subtraction result is equivalent to the comparison operation. The encryption processing device 1 can further perform an aggregation operation on the records that match the query in the comparison operation. In the aggregation operation, the encryption processing device 1 adds the records that match the query in the comparison operation to calculate the total, and further obtains the average value using division. In this way, for processing a query on an encrypted database, it is necessary to perform arithmetic operations such as addition, subtraction, multiplication, and division on the integers that make up the ciphertext, and comparison (the comparison is equivalent to the sign of the subtraction result). In particular, when obtaining a weighted average value, multiplication of a record and a weighting coefficient is required. And when using a Bit-wise type of ciphertext, it is considered that adder operations are frequently used in the processing. And as the bit length of the integers to be handled increases, the number of adders required also increases. The arithmetic operations are arithmetic operations that are homomorphic with respect to the encrypted numerical values regarded as the ciphertexts of each bit when the permutation using the input ciphertext is represented in binary. The encryption processing device 1 of the present embodiment does not perform arithmetic operations bit by bit using an adder for a Bit-wise type of ciphertext, but performs arithmetic operations and comparison between Integer-wise type of ciphertexts having integers as plaintexts, thereby making it possible to significantly reduce the query execution time.
[0121] Not limited to such aggregation of the database, arithmetic operations and comparison between integers are frequently used in various data processes using ciphertexts. As another example, fuzzy authentication and fuzzy search can be mentioned. Fuzzy authentication is, for example, biometric authentication using biometric data, and it is an absolute requirement that the biometric data, which remains unchanged throughout a person's life, be encrypted and kept secret. Fuzzy authentication performs authentication based on the correspondence between the biometric authentication data presented as an authentication request and the biometric authentication data registered in a database, but it does not check for a perfect match between the two, but rather judges whether they match based on a threshold value. Fuzzy search is a vague search method that presents data close to the query from a database as a search result even if the query and the record do not match exactly. In fuzzy authentication and fuzzy search, like the comparison and aggregation operations in the encrypted database described above, the encrypted database and the query are compared, and the comparison operation must be performed using data encrypted by homomorphic encryption. When calculating the inner product as the degree of match between the presented biometric authentication data and the registered biometric authentication data, multiplication is required.
[0122] In addition, Euclidean distance is often used for comparison in fuzzy authentication and fuzzy search. Calculating Euclidean distance requires a square operation. In bit-wise homomorphic encryption, multiplication takes time of O(N 2 ) full adder must be operated. Even a comparison operation using a simple subtraction requires the operation of a full adder of O(N). The cryptography processing device 1 of this embodiment does not perform arithmetic operations on a bit-wise ciphertext by using a full adder, but performs arithmetic operations and comparisons between Integer-wise ciphertexts having integers as plaintexts, thereby making it possible to significantly reduce the processing time required for fuzzy authentication and fuzzy search.
[0123] FIG. 18 is a block diagram illustrating an embodiment of a computer device. The configuration of the computer device 100 will be described with reference to FIG. The computer device 100 is, for example, a cryptographic processing device that processes various types of information. The computer device 100 includes a control circuit 101, a storage device 102, a reading / writing device 103, a recording medium 104, a communication interface 105, an input / output interface 106, an input device 107, and a display device 108. The communication interface 105 is connected to a network 200. The components are connected to each other via a bus 110. The cryptographic processing device 1 can be configured by appropriately selecting some or all of the components described in the computer device 100.
[0124] The control circuit 101 controls the entire computer device 100. The control circuit 101 is a processor such as a Central Processing Unit (CPU), a Field Programmable Gate Array (FPGA), an Application Specific Integrated Circuit (ASIC), or a Programmable Logic Device (PLD). The control circuit 101 functions as the control unit 10 in, for example, FIGS.
[0125] The storage device 102 stores various data. The storage device 102 is, for example, a memory such as a Read Only Memory (ROM) and a Random Access Memory (RAM), a Hard Disk (HD), or a Solid State Drive (SSD). The storage device 102 may store an information processing program that causes the control circuit 101 to function as the control unit 10 in Figs. 1, 9, 13, and 15. The storage device 102 functions as, for example, the storage unit 20 in Figs. 1, 9, 13, and 15.
[0126] When performing information processing, the cryptographic processing device 1 reads out a program stored in the storage device 102 into the RAM. The cryptographic processing device 1 of the first embodiment executes a program read into the RAM in the control circuit 101, thereby executing processes including one or more of the reception process, the first calculation process, the second calculation process, the third calculation process, the fourth calculation process, the fifth calculation process, the sixth calculation process, the seventh calculation process, the first bootstrap processing, the second bootstrap processing, the third bootstrap processing, and the output process. The cryptographic processing device 1 of the second embodiment executes a program read into the RAM in the control circuit 101, thereby executing processes including one or more of the reception process, the first calculation process, the second calculation process, the third calculation process, the fourth calculation process, the sixth calculation process, the seventh calculation process, the eighth calculation process, the ninth calculation process, the first bootstrap processing, the fourth bootstrap processing, the fifth bootstrap processing, and the output process.
[0127] The cryptographic processing device 1 of the fourth embodiment executes a program read into the RAM in the control circuit 101, thereby executing processes including one or more of the reception process, the first calculation process, the third calculation process, the fifth calculation process, the sixth calculation process, the seventh calculation process, the tenth calculation process, the first bootstrap processing, the second bootstrap processing, the third bootstrap processing, and the output process. Alternatively, the cryptographic processing device 1 of the fourth embodiment executes a program read into the RAM in the control circuit 101, thereby executing processing including one or more of the reception processing, the first calculation processing, the third calculation processing, the sixth calculation processing, the seventh calculation processing, the eighth calculation processing, the ninth calculation processing, the tenth calculation processing, the first bootstrap processing, the fourth bootstrap processing, the fifth bootstrap processing, and the output processing.
[0128] The cryptographic processing device 1 of the fifth embodiment executes a program read into the RAM in the control circuit 101, thereby executing processes including one or more of the reception process, the second calculation process, the fourth calculation process, the fifth calculation process, the sixth calculation process, the seventh calculation process, the eleventh calculation process, the first bootstrap processing, the second bootstrap processing, the third bootstrap processing, and the output process. Alternatively, the cryptographic processing device 1 of the fifth embodiment executes a program read into the RAM in the control circuit 101, thereby executing processing including one or more of the reception processing, the second calculation processing, the fourth calculation processing, the sixth calculation processing, the seventh calculation processing, the eighth calculation processing, the ninth calculation processing, the eleventh calculation processing, the first bootstrap processing, the fourth bootstrap processing, the fifth bootstrap processing, and the output processing. The program may be stored in a storage device of a server on the network 200 as long as the control circuit 101 can access the program via the communication interface 105 .
[0129] The reading / writing device 103 is controlled by the control circuit 101 and reads / writes data from / to a removable recording medium 104 . The recording medium 104 stores various data. For example, the recording medium 104 stores an information processing program. For example, the recording medium 104 is a non-volatile memory (non-transient recording medium) such as a Secure Digital (SD) memory card, a Floppy Disk (FD), a Compact Disc (CD), a Digital Versatile Disk (DVD), a Blu-ray (registered trademark) Disk (BD), or a flash memory.
[0130] The communication interface 105 communicably connects the computer device 100 to other devices via the network 200. The communication interface 105 functions as the communication unit 25 in, for example, FIGS. The input / output interface 106 is, for example, an interface that is detachably connected to various input devices. The input devices 107 connected to the input / output interface 106 include, for example, a keyboard and a mouse. The input / output interface 106 communicably connects the various input devices connected to the computer device 100. The input / output interface 106 outputs signals input from the various input devices connected to the control circuit 101 via the bus 110. The input / output interface 106 also outputs signals output from the control circuit 101 to the input / output device via the bus 110. The input / output interface 106 functions as the input unit 26 in, for example, FIGS. 1, 9, 13, and 15.
[0131] The display device 108 displays various information. The display device 108 is, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), a plasma display panel (PDP), an organic electroluminescence display (OLED), etc. The network 200 is, for example, a LAN, wireless communication, a P2P network, or the Internet, and communicatively connects the computer device 100 to other devices. It should be noted that the present embodiment is not limited to the embodiment described above, and various configurations or embodiments can be adopted without departing from the spirit of the present embodiment. [Explanation of symbols]
[0132] 1 encryption processing device, 10 control unit, 20 memory unit, 25 communication unit, 26 input unit, 100 computer device, 101 control circuit, 102 storage device, 103 reading / writing device, 104 recording medium, 105 communication interface, 106 input / output interface, 107 input device, 108 display device, 110 bus, 200 network
Claims
1. A cryptographic processing device for processing a ciphertext, comprising: The ciphertext is a fully homomorphic ciphertext having a plaintext in which an error having a predetermined variance is assigned to an integer within a predetermined value range, and a predetermined operation between integers can be performed without decryption, and the encryption processing device performs, as processing of the fully homomorphic ciphertext, multiplication of a first ciphertext and a second ciphertext, which are additively homomorphic to the plaintext, In the multiplication, the cryptographic processing device calculating a third ciphertext indicating a position of a plaintext in a homomorphic operation result obtained by performing a homomorphic operation on a ciphertext based on the first ciphertext and a ciphertext based on the second ciphertext, using a first polynomial having the same coefficients as a result of the operation; performing an operation on the first ciphertext and the second ciphertext by performing a homomorphic operation on the third ciphertext on the result of the operation to reduce the range of the plaintext to within a predetermined range within the range, and using a predetermined polynomial on the ciphertext; 4. A cryptographic processing device comprising:
2. 2. The cryptographic processing device according to claim 1, calculating a fourth ciphertext by homomorphically adding or homomorphically subtracting the third ciphertext from a result of homomorphically adding a ciphertext based on the second ciphertext to a ciphertext based on the first ciphertext, and reducing a range of the plaintext to a predetermined range within the range; calculating a fifth ciphertext by homomorphically adding or subtracting the third ciphertext to a result of homomorphically subtracting a ciphertext based on the second ciphertext from a ciphertext based on the first ciphertext, thereby reducing a range of a plaintext to a predetermined range within the range; performing an operation on the first ciphertext and the second ciphertext using the fourth ciphertext and the fifth ciphertext; 4. A cryptographic processing device comprising:
3. 2. The cryptographic processing device according to claim 1, calculating a fourth ciphertext by homomorphically adding or homomorphically subtracting the third ciphertext from a result of homomorphically adding a ciphertext based on the second ciphertext to a ciphertext based on the first ciphertext, and reducing a range of the plaintext to a predetermined range within the range; calculating a fifth ciphertext by homomorphically subtracting the first ciphertext or the second ciphertext from the fourth ciphertext, or by homomorphically subtracting the fourth ciphertext from the first ciphertext, thereby reducing the range of a plaintext to within a predetermined range within the range; performing an operation on the first ciphertext and the second ciphertext using the fourth ciphertext and the fifth ciphertext; 4. A cryptographic processing device comprising:
4. 2. The cryptographic processing device according to claim 1, calculating a fifth ciphertext by homomorphically adding or subtracting the third ciphertext to a result of homomorphically subtracting a ciphertext based on the second ciphertext from a ciphertext based on the first ciphertext, thereby reducing a range of a plaintext to a predetermined range within the range; calculating a fourth ciphertext by homomorphically adding the second ciphertext to the fifth ciphertext, or by homomorphically subtracting the first ciphertext from the fifth ciphertext, or by homomorphically subtracting the fifth ciphertext from the first ciphertext, thereby reducing the range of a plaintext to within a predetermined range within the range; performing an operation on the first ciphertext and the second ciphertext using the fourth ciphertext and the fifth ciphertext; 4. A cryptographic processing device comprising:
5. 5. The cryptographic processing device according to claim 2, calculating a sixth ciphertext by applying a second polynomial to the fourth ciphertext; calculating a seventh ciphertext by applying a third polynomial to the fifth ciphertext; performing homomorphic subtraction of the seventh ciphertext from the sixth ciphertext to calculate a ciphertext corresponding to a result of multiplication of the first ciphertext and the second ciphertext.
4. A cryptographic processing device comprising:
6. 5. The cryptographic processing device according to claim 2, calculating an eighth ciphertext based on the first coefficient and a ninth ciphertext based on the second coefficient using a fourth polynomial having a first coefficient and a second coefficient on the fourth ciphertext; calculating a tenth cipher text based on the third coefficient and an eleventh cipher text based on the fourth coefficient using a fifth polynomial having a third coefficient and a fourth coefficient on the fifth cipher text; performing homomorphic subtraction of the tenth ciphertext from the eighth ciphertext to calculate a ciphertext corresponding to the most significant bits of a multiplication result of the plaintexts of the first ciphertext and the second ciphertext; and performing homomorphic subtraction of the eleventh ciphertext from the ninth ciphertext to calculate a ciphertext corresponding to the least significant bits of the multiplication result.
4. A cryptographic processing device comprising:
7. 7. The cryptographic processing device according to claim 6, a first table storing calculated values of the first coefficient and a second table storing calculated values of the second coefficient; calculating the eighth ciphertext or the ninth ciphertext by simultaneously referring to the first table and the second table by using the fourth polynomial for the fourth ciphertext; a third table storing the calculated values of the third coefficient and a fourth table storing the calculated values of the fourth coefficient, calculating the tenth ciphertext or the eleventh ciphertext by simultaneously referring to the third table and the fourth table by using the fifth polynomial for the fifth ciphertext; 4. A cryptographic processing device comprising:
8. 2. The cryptographic processing device according to claim 1, Dividing a coefficient of the first ciphertext by 2 to calculate a ciphertext based on the first ciphertext, and dividing a coefficient of the second ciphertext by 2 to calculate a ciphertext based on the second ciphertext.
4. A cryptographic processing device comprising:
9. In the cryptographic processing device according to claim 1, a ciphertext based on the first ciphertext is a first ciphertext, and a ciphertext based on the second ciphertext is a second ciphertext; calculating the third ciphertext by applying the first polynomial to a result of a homomorphic operation performed on the first ciphertext and the second ciphertext, the coefficient of the result being divided by 2; 4. A cryptographic processing device comprising:
10. 2. The cryptographic processing device according to claim 1, a calculation unit that calculates a new ciphertext by using a predetermined polynomial on the ciphertext, the calculation unit performing a process of reducing the number of coefficients on the input ciphertext before calculating the new ciphertext by using the predetermined polynomial; 4. A cryptographic processing device comprising:
11. 2. The cryptographic processing device according to claim 1, By performing the predetermined calculation, a process related to fuzzy authentication or fuzzy search is performed using the input ciphertext.
4. A cryptographic processing device comprising:
12. 2. The cryptographic processing device according to claim 1, performing the predetermined operation to process a query to an encrypted database based on the input ciphertext; 4. A cryptographic processing device comprising:
13. A cryptographic processing method for a cryptographic processing device that processes a ciphertext, the cryptographic processing device comprising a receiving means, a first calculation means, and a second calculation means, comprising: The ciphertext is a fully homomorphic ciphertext having a plaintext in which an error having a predetermined variance is assigned to an integer within a predetermined value range, and a predetermined operation between integers can be performed without decryption, and the encryption processing device performs, as processing of the fully homomorphic ciphertext, multiplication of a first ciphertext and a second ciphertext, which are additively homomorphic to the plaintext, the receiving means receives an input of the first ciphertext and the second ciphertext to be multiplied; the first calculation means calculates a third ciphertext indicating a position of a plaintext in a result of a homomorphic operation performed on a ciphertext based on the first ciphertext and a ciphertext based on the second ciphertext, using a first polynomial having the same coefficients for all the coefficients, and stores the third ciphertext in a storage device; the second calculation means performs an operation on the first ciphertext and the second ciphertext by performing a homomorphic operation on the operation result of the third ciphertext and reducing a range of the plaintext to a predetermined range within the range, and using a predetermined polynomial on the ciphertext.
13. A cryptographic processing method comprising:
14. A cryptographic processing program for causing a processor to execute a cryptographic processing method for processing a ciphertext, the ciphertext is a fully homomorphic ciphertext having a plaintext in which a value to which an error having a predetermined variance is given within a predetermined value range is associated with an integer, and a predetermined operation between integers can be performed without decryption, and the processor performs multiplication of a first ciphertext and a second ciphertext, which are each additively homomorphic with respect to the plaintext, as processing of the fully homomorphic ciphertext based on the encryption processing program; In the multiplication, the processor calculates a third ciphertext indicating a position of a plaintext in a result of a homomorphic operation performed on a ciphertext based on the first ciphertext and a ciphertext based on the second ciphertext, using a first polynomial having the same coefficients as a result of the homomorphic operation performed on the ciphertext based on the first ciphertext and the ciphertext based on the second ciphertext, based on the encryption process program; the processor performs an operation on the first ciphertext and the second ciphertext based on the encryption processing program by performing a homomorphic operation on the operation result of the third ciphertext and the ciphertext, the range of the plaintext being reduced to a predetermined range within the range, and using a predetermined polynomial on the ciphertext.
4. A cryptographic processing program comprising:
Citation Information
Patent Citations
JPP7187074B
Cryptographic method, systems and services for assessing univariate or multivariate true value functions on encrypted data
WO2021229157A1
Encryption processing device, encryption processing method, and encryption processing program
WO2023084895A1